cbcvebase.
CVE-2024-42240
published 2024-08-07

CVE-2024-42240: In the Linux kernel, the following vulnerability has been resolved: x86/bhi: Avoid warning in #DB handler due to BHI mitigation When BHI mitigation is enabled…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: x86/bhi: Avoid warning in #DB handler due to BHI mitigation When BHI mitigation is enabled, if SYSENTER is invoked with the TF flag set then entry_SYSENTER_compat() uses CLEAR_BRANCH_HISTORY and calls the clear_bhb_loop() before the TF flag is cleared. This causes the #DB handler (exc_debug_kernel()) to issue a warning because single-step is used outside the entry_SYSENTER_compat() function. To address this issue, entry_SYSENTER_compat() should use CLEAR_BRANCH_HISTORY after making sure the TF flag is cleared. The problem can be reproduced with the following sequence: $ cat sysenter_step.c int main() { asm("pushf; pop %ax; bts $8,%ax; push %ax; popf; sysenter"); } $ gcc -o sysenter_step sysenter_step.c $ ./sysenter_step Segmentation fault (core dumped) The program is expected to crash, and the #DB handler will issue a warning. Kernel log: WARNING: CPU: 27 PID: 7000 at arch/x86/kernel/traps.c:1009 exc_debug_kernel+0xd2/0x160 ... RIP: 0010:exc_debug_kernel+0xd2/0x160 ... Call Trace: ? show_regs+0x68/0x80 ? __warn+0x8c/0x140 ? exc_debug_kernel+0xd2/0x160 ? report_bug+0x175/0x1a0 ? handle_bug+0x44/0x90 ? exc_invalid_op+0x1c/0x70 ? asm_exc_invalid_op+0x1f/0x30 ? exc_debug_kernel+0xd2/0x160 exc_debug+0x43/0x50 asm_exc_debug+0x1e/0x40 RIP: 0010:clear_bhb_loop+0x0/0xb0 ... ? entry_SYSENTER_compat_after_hwframe+0x6e/0x8d [ bp: Massage commit message. ]

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
debianlinux-6.1< linux 6.1.106-1 (bookworm)linux 6.1.106-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 07dbb10f153f483e8249acebdffedf922e2ec2e1 < a765679defe1dc1b8fa01928a6ad6361e72a1364a765679defe1dc1b8fa01928a6ad6361e72a1364
linuxlinux>= 5.15.154 < 5.15.1635.15.163
linuxlinux>= 6.1.85 < 6.1.1006.1.100
linuxlinux>= 6.6.26 < 6.6.416.6.41
linuxlinux>= 6.8.5 < 6.96.9
linuxlinux>= 7390db8aea0d64e9deb28b8e1ce716f5020c7ee5 < 08518d48e5b744620524f0acd7c26c19bda7f51308518d48e5b744620524f0acd7c26c19bda7f513
linuxlinux>= 7390db8aea0d64e9deb28b8e1ce716f5020c7ee5 < ac8b270b61d48fcc61f052097777e3b5e11591e0ac8b270b61d48fcc61f052097777e3b5e11591e0
linuxlinux>= bd53ec80f21839cfd4d852a6088279d602d67e5b < db56615e96c439e13783d7715330e824b4fd4b84db56615e96c439e13783d7715330e824b4fd4b84
linuxlinux>= eb36b0dce2138581bc6b5e39d0273cb4c96ded81 < dae3543db8f0cf8ac1a198c3bb4b6e3c24d576cfdae3543db8f0cf8ac1a198c3bb4b6e3c24d576cf
linuxlinux_kernel>= 0 < 6.1.106-16.1.106-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 6.9.10-16.9.10-1
linuxlinux_kernel>= 0 < 5.4.0-202.2225.4.0-202.222
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 0 < 4.4.0-261.2954.4.0-261.295
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 5.15.163 < 6.1.1006.1.100
linuxlinux_kernel>= 6.2 < 6.6.416.6.41
linuxlinux_kernel>= 6.7 < 6.9.106.9.10
msrcazl3_kernel_6.6.35.1-5_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.