PT-2024-5015 · Linux+10 · Linux Kernel+10

Andrin Bertschi

+4

·

Published

2024-01-29

·

Updated

2026-03-14

·

CVE-2024-25742

CVSS v3.1

6.5

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.9
Description: The issue is related to the implementation of the SEV-SNP and SEV-ES mechanisms in the Linux kernel. An untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and trigger its handler, potentially affecting the confidentiality and integrity of protected information. This can be done by injecting a virtual interrupt, which can have an impact on the system's security.
Recommendations: For Linux kernel versions prior to 6.9, consider disabling the virtual interrupt 29 (#VC) handler as a temporary workaround until a patch is available. Restrict access to the SEV-SNP and SEV-ES mechanisms to minimize the risk of exploitation. Update to a version of the Linux kernel that is 6.9 or later to fully resolve the issue.

Fix

LPE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:2758
ALSA-2024:2950
ALSA-2024:3138
ALT-PU-2024-14732
ALT-PU-2024-14734
ALT-PU-2024-14950
BDU:2024-05539
CESA-2024_2950
CESA-2024_3138
CVE-2024-25742
ECHO-7B47-31BE-12A9
INFSA-2024_2758
INFSA-2024_2950
INFSA-2024_3138
OPENSUSE-SU-2024:14336-1
OPENSUSE-SU-2024_1321-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
OPENSUSE-SU-2024_1641-1
RHSA-2024:2627
RHSA-2024:2628
RHSA-2024:2758
RHSA-2024:2950
RHSA-2024:3138
RHSA-2024:3421
RHSA-2024:3810
RHSA-2024_2758
RHSA-2024_2950
RHSA-2024_3138
RLSA-2024:2758
RLSA-2024:2950
RLSA-2024:3138
SUSE-SU-2024:1320-1
SUSE-SU-2024:1321-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1
SUSE-SU-2024:1641-1
USN-6921-1
USN-6921-2
USN-6923-1
USN-6923-2
USN-6927-1
USN-6952-1
USN-6952-2
USN-6956-1
USN-6957-1
USN-7019-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu