PT-2024-7720 · Linux+6 · Linux Kernel+6

Published

2024-02-19

·

Updated

2025-09-29

·

CVE-2024-27437

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to errors in resource management within the vfio intx set signal() function of the Linux kernel's vfio/pci component. This could allow an attacker to cause a denial of service. The problem arises from the handling of interrupts for devices that require masking at the irqchip for INTx, specifically those without DisINTx support. The IRQ is enabled in request irq() and then disabled as necessary, creating a window where the interrupt could fire, resulting in the IRQ incrementing the disable depth twice, which would be unrecoverable for a user due to the masked flag preventing nested enables through vfio. The solution involves inverting the logic using IRQF NO AUTOEN so that exclusive INTx is never auto-enabled, and then unmasking as required.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
AZL-59261
BDU:2024-09183
CVE-2024-27437
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_9315
OESA-2024-1520
OESA-2024-1524
OESA-2024-1526
OESA-2024-1535
OESA-2024-1536
OESA-2024-1541
OPENSUSE-SU-2024_2947-1
RHSA-2024:9315
RHSA-2024_9315
SUSE-SU-2024:2892-1
SUSE-SU-2024:2894-1
SUSE-SU-2024:2901-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:2940-1
SUSE-SU-2024:2947-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1
USN-6816-1
USN-6817-1
USN-6817-2
USN-6817-3
USN-6878-1
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6919-1
USN-6927-1
USN-7019-1
USN-7028-1
USN-7028-2
USN-7039-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu