PT-2024-3785 · Linux+5 · Linux Kernel+5
Published
2024-01-17
·
Updated
2024-10-04
·
CVE-2024-26620
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the
vfio ap mdev filter matrix function in the Linux kernel, which is responsible for updating the guest's AP configuration by filtering the matrix of adapters and domains assigned to the mdev. Under certain circumstances, inspecting only the APID of the new adapter or APQI of the new domain can result in passing AP queues through to a guest that are not bound to the vfio ap device driver. This violates the Linux device model requirement that a guest shall only be given access to devices bound to the device driver facilitating their pass-through.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu