PT-2024-8228 · Linux+5 · Linux Kernel+5

Published

2024-02-16

·

Updated

2025-02-03

·

CVE-2024-35804

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the KVM component of the Linux kernel, specifically with the emulation of atomic instructions. When KVM emulates an atomic access on behalf of the guest, it may corrupt guest memory during live migration by writing to guest memory without informing userspace that the page is dirty. The problem occurred because marking the page dirty was unintentionally dropped when KVM's emulated CMPXCHG was converted to do a user access. The fix involves marking the target gfn dirty if the CMPXCHG by KVM is attempted and doesn't fault, even if the CMPXCHG fails.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Leak

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09772
CVE-2024-35804
SUSE-SU-2024:2008-1
SUSE-SU-2024:2019-1
SUSE-SU-2024:2135-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2203-1
SUSE-SU-2024:2973-1
SUSE-SU-2025:20008-1
SUSE-SU-2025:20028-1
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6917-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu