cbcvebase.
CVE-2024-36916
published 2024-05-30

CVE-2024-36916: In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.73%
50.8th percentile
In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where sometimes iocg->delay is shifted right by a number that is too large, resulting in undefined behavior on some architectures. [ 186.556576] ------------[ cut here ]------------ UBSAN: shift-out-of-bounds in block/blk-iocost.c:1366:23 shift exponent 64 is too large for 64-bit type 'u64' (aka 'unsigned long long') CPU: 16 PID: 0 Comm: swapper/16 Tainted: G S E N 6.9.0-0_fbk700_debug_rc2_kbuilder_0_gc85af715cac0 #1 Hardware name: Quanta Twin Lakes MP/Twin Lakes Passive MP, BIOS F09_3A23 12/08/2020 Call Trace: dump_stack_lvl+0x8f/0xe0 __ubsan_handle_shift_out_of_bounds+0x22c/0x280 iocg_kick_delay+0x30b/0x310 ioc_timer_fn+0x2fb/0x1f80 __run_timer_base+0x1b6/0x250 ... Avoid that undefined behavior by simply taking the "delay = 0" branch if the shift is too large. I am not sure what the symptoms of an undefined value delay will be, but I suspect it could be more than a little annoying to debug.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 5160a5a53c0c4ae3708959d9465ea43ad5d90542 < 62accf6c1d7b433752cb3591bba8967b7a801ad562accf6c1d7b433752cb3591bba8967b7a801ad5
linuxlinux>= 5160a5a53c0c4ae3708959d9465ea43ad5d90542 < 844fc023e9f14a4fb1de5ae1eaefafd6d69c5fa1844fc023e9f14a4fb1de5ae1eaefafd6d69c5fa1
linuxlinux>= 5160a5a53c0c4ae3708959d9465ea43ad5d90542 < f6add0a6f78dc6360b822ca4b6f9f2f14174c8caf6add0a6f78dc6360b822ca4b6f9f2f14174c8ca
linuxlinux>= 5160a5a53c0c4ae3708959d9465ea43ad5d90542 < ce0e99cae00e3131872936713b7f55eefd53ab86ce0e99cae00e3131872936713b7f55eefd53ab86
linuxlinux>= 5160a5a53c0c4ae3708959d9465ea43ad5d90542 < 488dc6808cb8369685f18cee81e88e7052ac153b488dc6808cb8369685f18cee81e88e7052ac153b
linuxlinux>= 5160a5a53c0c4ae3708959d9465ea43ad5d90542 < beaa51b36012fad5a4d3c18b88a617aea7a9b96dbeaa51b36012fad5a4d3c18b88a617aea7a9b96d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 5.10 < 5.10.2175.10.217
linuxlinux_kernel>= 5.11 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.