cbcvebase.
CVE-2024-36953
published 2024-05-30

CVE-2024-36953: In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.9th percentile
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU that matches the user-provided CPUID, which (of course) may not be valid. If the ID is invalid, kvm_get_vcpu_by_id() returns NULL, which isn't handled gracefully. Similar to the GICv3 uaccess flow, check that kvm_get_vcpu_by_id() actually returns something and fail the ioctl if not.

Affected

23 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= 7d450e2821710718fd6703e9c486249cee913bab < 4404465a1bee3607ad90a4c5f9e16dfd75b857284404465a1bee3607ad90a4c5f9e16dfd75b85728
linuxlinux>= 7d450e2821710718fd6703e9c486249cee913bab < 17db92da8be5dd3bf63c01f4109fe47db64fc66f17db92da8be5dd3bf63c01f4109fe47db64fc66f
linuxlinux>= 7d450e2821710718fd6703e9c486249cee913bab < 3a5b0378ac6776c7c31b18e0f3c1389bd6005e803a5b0378ac6776c7c31b18e0f3c1389bd6005e80
linuxlinux>= 7d450e2821710718fd6703e9c486249cee913bab < 8d6a1c8e3de36cb0f5e866f1a582b00939e231048d6a1c8e3de36cb0f5e866f1a582b00939e23104
linuxlinux>= 7d450e2821710718fd6703e9c486249cee913bab < 01981276d64e542c177b243f7c979fee855d548701981276d64e542c177b243f7c979fee855d5487
linuxlinux>= 7d450e2821710718fd6703e9c486249cee913bab < 6ddb4f372fc63210034b903d96ebbeb3c7195adb6ddb4f372fc63210034b903d96ebbeb3c7195adb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.218-15.10.218-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 6.8.11-16.8.11-1
linuxlinux_kernel>= 0 < 5.4.0-202.2225.4.0-202.222
linuxlinux_kernel>= 0 < 5.15.0-118.1285.15.0-118.128
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 4.7 < 5.10.2175.10.217
linuxlinux_kernel>= 5.11 < 5.15.1595.15.159
linuxlinux_kernel>= 5.16 < 6.1.916.1.91
linuxlinux_kernel>= 6.2 < 6.6.316.6.31
linuxlinux_kernel>= 6.7 < 6.8.106.8.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.