cbcvebase.
CVE-2024-53135
published 2024-12-04

CVE-2024-53135: In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN Hide KVM's…

PriorityP425medium6.5CVSS 3.1
AVLACLPRLUINSCCNINAH
EPSS
0.23%
14.0th percentile
In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN Hide KVM's pt_mode module param behind CONFIG_BROKEN, i.e. disable support for virtualizing Intel PT via guest/host mode unless BROKEN=y. There are myriad bugs in the implementation, some of which are fatal to the guest, and others which put the stability and health of the host at risk. For guest fatalities, the most glaring issue is that KVM fails to ensure tracing is disabled, and *stays* disabled prior to VM-Enter, which is necessary as hardware disallows loading (the guest's) RTIT_CTL if tracing is enabled (enforced via a VMX consistency check). Per the SDM: If the logical processor is operating with Intel PT enabled (if IA32_RTIT_CTL.TraceEn = 1) at the time of VM entry, the "load IA32_RTIT_CTL" VM-entry control must be 0. On the host side, KVM doesn't validate the guest CPUID configuration provided by userspace, and even worse, uses the guest configuration to decide what MSRs to save/load at VM-Enter and VM-Exit. E.g. configuring guest CPUID to enumerate more address ranges than are supported in hardware will result in KVM trying to passthrough, save, and load non-existent MSRs, which generates a variety of WARNs, ToPA ERRORs in the host, a potential deadlock, etc.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= f99e3daf94ff35dd4a878d32ff66e1fd35223ad6 < c3742319d021f5aa3a0a8c828485fee14753f6dec3742319d021f5aa3a0a8c828485fee14753f6de
linuxlinux>= f99e3daf94ff35dd4a878d32ff66e1fd35223ad6 < d4b42f926adcce4e5ec193c714afd9d37bba8e5bd4b42f926adcce4e5ec193c714afd9d37bba8e5b
linuxlinux>= f99e3daf94ff35dd4a878d32ff66e1fd35223ad6 < b8a1d572478b6f239061ee9578b2451bf2f021c2b8a1d572478b6f239061ee9578b2451bf2f021c2
linuxlinux>= f99e3daf94ff35dd4a878d32ff66e1fd35223ad6 < e6716f4230a8784957273ddd27326264b27b9313e6716f4230a8784957273ddd27326264b27b9313
linuxlinux>= f99e3daf94ff35dd4a878d32ff66e1fd35223ad6 < d28b059ee4779b5102c5da6e929762520510e406d28b059ee4779b5102c5da6e929762520510e406
linuxlinux>= f99e3daf94ff35dd4a878d32ff66e1fd35223ad6 < b91bb0ce5cd7005b376eac690ec664c1b56372ecb91bb0ce5cd7005b376eac690ec664c1b56372ec
linuxlinux>= f99e3daf94ff35dd4a878d32ff66e1fd35223ad6 < aa0d42cacf093a6fcca872edc954f6f812926a17aa0d42cacf093a6fcca872edc954f6f812926a17
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 6.11.10-16.11.10-1
linuxlinux_kernel>= 0 < 5.4.0-211.2315.4.0-211.231
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.