cbcvebase.
CVE-2024-26598
published 2024-02-23

CVE-2024-26598: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.2th percentile
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF scenario in the case of an LPI translation cache hit racing with an operation that invalidates the cache, such as a DISCARD ITS command. The root of the problem is that vgic_its_check_cache() does not elevate the refcount on the vgic_irq before dropping the lock that serializes refcount changes. Have vgic_its_check_cache() raise the refcount on the returned vgic_irq and add the corresponding decrement after queueing the interrupt.

Affected

22 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.76-1 (bookworm)linux 6.1.76-1 (bookworm)
linuxlinux
linuxlinux>= 6211753fdfd05af9e08f54c8d0ba3ee516034878 < d04acadb6490aa3314f9c9e087691e55de153b88d04acadb6490aa3314f9c9e087691e55de153b88
linuxlinux>= 6211753fdfd05af9e08f54c8d0ba3ee516034878 < ba7be666740847d967822bed15500656b26bc703ba7be666740847d967822bed15500656b26bc703
linuxlinux>= 6211753fdfd05af9e08f54c8d0ba3ee516034878 < 12c2759ab1343c124ed46ba48f27bd1ef5d2dff412c2759ab1343c124ed46ba48f27bd1ef5d2dff4
linuxlinux>= 6211753fdfd05af9e08f54c8d0ba3ee516034878 < dba788e25f05209adf2b0175eb1691dc89fb1ba6dba788e25f05209adf2b0175eb1691dc89fb1ba6
linuxlinux>= 6211753fdfd05af9e08f54c8d0ba3ee516034878 < 65b201bf3e9af1b0254243a5881390eda56f72d165b201bf3e9af1b0254243a5881390eda56f72d1
linuxlinux>= 6211753fdfd05af9e08f54c8d0ba3ee516034878 < dd3956a1b3dd11f46488c928cb890d6937d1ca80dd3956a1b3dd11f46488c928cb890d6937d1ca80
linuxlinux>= 6211753fdfd05af9e08f54c8d0ba3ee516034878 < ad362fe07fecf0aba839ff2cc59a3617bd42c33fad362fe07fecf0aba839ff2cc59a3617bd42c33f
linuxlinux_kernel>= 0 < 5.10.209-15.10.209-1
linuxlinux_kernel>= 0 < 6.1.76-16.1.76-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 6.6.15-16.6.15-1
linuxlinux_kernel>= 0 < 5.4.0-181.2015.4.0-181.201
linuxlinux_kernel>= 0 < 5.15.0-102.1125.15.0-102.112
linuxlinux_kernel>= 5.11 < 5.15.1485.15.148
linuxlinux_kernel>= 5.16 < 6.1.756.1.75
linuxlinux_kernel>= 5.4 < 5.4.2695.4.269
linuxlinux_kernel>= 5.5 < 5.10.2095.10.209
linuxlinux_kernel>= 6.2 < 6.6.146.6.14
linuxlinux_kernel>= 6.7 < 6.7.26.7.2

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.