cbcvebase.
CVE-2024-46738
published 2024-09-18

CVE-2024-46738: In the Linux kernel, the following vulnerability has been resolved: VMCI: Fix use-after-free when removing resource in vmci_resource_remove() When removing a…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved: VMCI: Fix use-after-free when removing resource in vmci_resource_remove() When removing a resource from vmci_resource_table in vmci_resource_remove(), the search is performed using the resource handle by comparing context and resource fields. It is possible though to create two resources with different types but same handle (same context and resource fields). When trying to remove one of the resources, vmci_resource_remove() may not remove the intended one, but the object will still be freed as in the case of the datagram type in vmci_datagram_destroy_handle(). vmci_resource_table will still hold a pointer to this freed resource leading to a use-after-free vulnerability. BUG: KASAN: use-after-free in vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline] BUG: KASAN: use-after-free in vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147 Read of size 4 at addr ffff88801c16d800 by task syz-executor197/1592 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x82/0xa9 lib/dump_stack.c:106 print_address_description.constprop.0+0x21/0x366 mm/kasan/report.c:239 __kasan_report.cold+0x7f/0x132 mm/kasan/report.c:425 kasan_report+0x38/0x51 mm/kasan/report.c:442 vmci_handle_is_equal include/linux/vmw_vmci_defs.h:142 [inline] vmci_resource_remove+0x3a1/0x410 drivers/misc/vmw_vmci/vmci_resource.c:147 vmci_qp_broker_detach+0x89a/0x11b9 drivers/misc/vmw_vmci/vmci_queue_pair.c:2182 ctx_free_ctx+0x473/0xbe1 drivers/misc/vmw_vmci/vmci_context.c:444 kref_put include/linux/kref.h:65 [inline] vmci_ctx_put drivers/misc/vmw_vmci/vmci_context.c:497 [inline] vmci_ctx_destroy+0x170/0x1d6 drivers/misc/vmw_vmci/vmci_context.c:195 vmci_host_close+0x125/0x1ac drivers/misc/vmw_vmci/vmci_host.c:143 __fput+0x261/0xa34 fs/file_table.c:282 task_work_run+0xf0/0x194 kernel/task_work.c:164 tracehook_notify_resume include/linux/tracehook.h:189 [inline] exit_to_user_mode_loop+0x184/0x18

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= bc63dedb7d46a7d690c6b6edf69136b88af06cc6 < f6365931bf7c07b2b397dbb06a4f6573cc9fae73f6365931bf7c07b2b397dbb06a4f6573cc9fae73
linuxlinux>= bc63dedb7d46a7d690c6b6edf69136b88af06cc6 < b243d52b5f6f59f9d39e69b191fb3d58b94a43b1b243d52b5f6f59f9d39e69b191fb3d58b94a43b1
linuxlinux>= bc63dedb7d46a7d690c6b6edf69136b88af06cc6 < 6c563a29857aa8053b67ee141191f69757f27f6e6c563a29857aa8053b67ee141191f69757f27f6e
linuxlinux>= bc63dedb7d46a7d690c6b6edf69136b88af06cc6 < ef5f4d0c5ee22d4f873116fec844ff6edaf3fa7def5f4d0c5ee22d4f873116fec844ff6edaf3fa7d
linuxlinux>= bc63dedb7d46a7d690c6b6edf69136b88af06cc6 < b9efdf333174468651be40390cbc79c9f55d9cceb9efdf333174468651be40390cbc79c9f55d9cce
linuxlinux>= bc63dedb7d46a7d690c6b6edf69136b88af06cc6 < 39e7e593418ccdbd151f2925fa6be1a616d16c9639e7e593418ccdbd151f2925fa6be1a616d16c96
linuxlinux>= bc63dedb7d46a7d690c6b6edf69136b88af06cc6 < 00fe5292f081f8d773e572df8e03bf6e1855fe4900fe5292f081f8d773e572df8e03bf6e1855fe49
linuxlinux>= bc63dedb7d46a7d690c6b6edf69136b88af06cc6 < 48b9a8dabcc3cf5f961b2ebcd8933bf9204babb748b9a8dabcc3cf5f961b2ebcd8933bf9204babb7
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 0 < 4.4.0-261.2954.4.0-261.295
linuxlinux_kernel>= 0 < 4.15.0-231.2434.15.0-231.243
linuxlinux_kernel>= 3.9 < 4.19.3224.19.322
linuxlinux_kernel>= 4.20 < 5.4.2845.4.284
linuxlinux_kernel>= 5.11 < 5.15.1675.15.167
linuxlinux_kernel>= 5.16 < 6.1.1106.1.110

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.