PT-2024-26819 · Linux +5 · Linux Kernel +5
Yihuang Yu
·
Published
2024-04-05
·
Updated
2025-01-16
·
CVE-2024-35980
7.5
High
Base vector | Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A vulnerability has been resolved in the Linux kernel related to the arm64: tlb: Fix TLBI RANGE operand. The issue arises when the KVM/arm64 relies on the TLBI RANGE feature to flush TLBs during live migration, but the operand passed to the TLBI RANGE instruction is not correctly sorted out. This leads to a crash on the destination VM after live migration because TLBs are not flushed completely, and some dirty pages are missed. The problem is caused by the commit 117940aa6e5f, which defined `kvm tlb flush vmid range()`. The fix involves extending ` TLBI RANGE NUM()` to support the combination of SCALE#3 and NUM#31.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Underflow
Weakness Enumeration
Related Identifiers
Affected Products
References · 3303
- 🔥 https://github.com/MaherAzzouzi/CVE-2024-26817-amdkfd⭐ 7 🔗 2 · Exploit
- https://safe-surf.ru/specialists/bulletins-nkcki/719539 · Security Note
- https://bdu.fstec.ru/vul/2025-07941 · Security Note
- https://bdu.fstec.ru/vul/2025-01783 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27006 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-35875 · Security Note
- https://ubuntu.com/security/CVE-2024-27005 · Vendor Advisory
- https://bdu.fstec.ru/vul/2025-03116 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-26936 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/721321 · Security Note
- https://bdu.fstec.ru/vul/2024-04218 · Security Note
- https://bdu.fstec.ru/vul/2025-03115 · Security Note
- https://bdu.fstec.ru/vul/2025-03492 · Security Note
- https://bdu.fstec.ru/vul/2025-01651 · Security Note
- https://ubuntu.com/security/CVE-2024-35963 · Vendor Advisory