PT-2024-29763 · Linux+6 · Linux Kernel+6
Li Zhang
·
Published
2024-05-16
·
Updated
2026-05-26
·
CVE-2024-42134
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability has been resolved in the Linux kernel related to the virtio-pci module. The issue involves the
vp dev->is avq function being empty in certain installations, specifically when virtio pci legacy does not assign a value to it. This emptiness can cause the guest system to crash when the virsh Attach device command is used. The vulnerability is related to the vp del vqs function in the virtio pci common.c file, where vp dev->is avq is used to determine whether it is an admin virtqueue.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu