CVE-2024-26976 — Uncontrolled Resource Consumption in Linux
Severity
7.0HIGHNVD
OSV5.5
EPSS
0.0%
top 99.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateSep 18
Description
In the Linux kernel, the following vulnerability has been resolved:
KVM: Always flush async #PF workqueue when vCPU is being destroyed
Always flush the per-vCPU async #PF workqueue when a vCPU is clearing its
completion queue, e.g. when a VM and all its vCPUs is being destroyed.
KVM must ensure that none of its workqueue callbacks is running when the
last reference to the KVM _module_ is put. Gifting a reference to the
associated VM prevents the workqueue callback from dereferencing freed
vCPU…
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9
Affected Packages5 packages
▶CVEListV5linux/linuxaf585b921e5d1e919947c4b1164b59507fe7cd7b — ab2c2f5d9576112ad22cfd3798071cb74693b1f5+9
Also affects: Debian Linux 10.0
Patches
🔴Vulnerability Details
20📋Vendor Advisories
20💬Community
1Bugzilla▶
CVE-2024-26976 kernel: KVM: Always flush async #PF workqueue when vCPU is being destroyed↗2024-05-01