cbcvebase.
CVE-2024-42135
published 2024-07-30

CVE-2024-42135: In the Linux kernel, the following vulnerability has been resolved: vhost_task: Handle SIGKILL by flushing work and exiting Instead of lingering until the…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.5th percentile
In the Linux kernel, the following vulnerability has been resolved: vhost_task: Handle SIGKILL by flushing work and exiting Instead of lingering until the device is closed, this has us handle SIGKILL by: 1. marking the worker as killed so we no longer try to use it with new virtqueues and new flush operations. 2. setting the virtqueue to worker mapping so no new works are queued. 3. running all the exiting works.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.9-1 (forky)linux 6.9.9-1 (forky)
linuxlinux
linuxlinux>= f9010dbdce911ee1f1af1398a24b1f9f992e0080 < abe067dc3a662eef7d5cddbbc41ed50a0b68b0afabe067dc3a662eef7d5cddbbc41ed50a0b68b0af
linuxlinux>= f9010dbdce911ee1f1af1398a24b1f9f992e0080 < dec987fe2df670827eb53b97c9552ed8dfc63ad4dec987fe2df670827eb53b97c9552ed8dfc63ad4
linuxlinux>= f9010dbdce911ee1f1af1398a24b1f9f992e0080 < db5247d9bf5c6ade9fd70b4e4897441e0269b233db5247d9bf5c6ade9fd70b4e4897441e0269b233
linuxlinux_kernel< 6.6.396.6.39
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 6.7 < 6.9.96.9.9
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.