CVE-2024-26810

In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Lock external INTx masking ops Mask operations through config space changes to DisINTx may race INTx configuration changes via ioctl. Create wrappers that add locking for paths outside of the core interrupt code. In particular, irq_type is updated holding igate, therefore testing is_intx() requires holding igate. For example clearing DisINTx from config space can otherwise race changes of the interrupt configuration. This aligns interfaces which may trigger the INTx eventfd into two camps, one side serialized by igate and the other only enabled while INTx is configured. A subsequent patch introduces synchronization for the latter flows.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

08 Apr 2025, 19:20

Type Values Removed Values Added
CWE CWE-362
References () https://git.kernel.org/stable/c/03505e3344b0576fd619416793a31eae9c5b73bf - () https://git.kernel.org/stable/c/03505e3344b0576fd619416793a31eae9c5b73bf - Patch
References () https://git.kernel.org/stable/c/04a4a017b9ffd7b0f427b8c376688d14cb614651 - () https://git.kernel.org/stable/c/04a4a017b9ffd7b0f427b8c376688d14cb614651 - Patch
References () https://git.kernel.org/stable/c/1e71b6449d55179170efc8dee8664510bb813b42 - () https://git.kernel.org/stable/c/1e71b6449d55179170efc8dee8664510bb813b42 - Patch
References () https://git.kernel.org/stable/c/3dd9be6cb55e0f47544e7cdda486413f7134e3b3 - () https://git.kernel.org/stable/c/3dd9be6cb55e0f47544e7cdda486413f7134e3b3 - Patch
References () https://git.kernel.org/stable/c/3fe0ac10bd117df847c93408a9d428a453cd60e5 - () https://git.kernel.org/stable/c/3fe0ac10bd117df847c93408a9d428a453cd60e5 - Patch
References () https://git.kernel.org/stable/c/6fe478d855b20ac1eb5da724afe16af5a2aaaa40 - () https://git.kernel.org/stable/c/6fe478d855b20ac1eb5da724afe16af5a2aaaa40 - Patch
References () https://git.kernel.org/stable/c/810cd4bb53456d0503cc4e7934e063835152c1b7 - () https://git.kernel.org/stable/c/810cd4bb53456d0503cc4e7934e063835152c1b7 - Patch
References () https://git.kernel.org/stable/c/ec73e079729258a05452356cf6d098bf1504d5a6 - () https://git.kernel.org/stable/c/ec73e079729258a05452356cf6d098bf1504d5a6 - Patch
References () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html - Mailing List, Third Party Advisory
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux

21 Nov 2024, 09:03

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html -
References () https://git.kernel.org/stable/c/03505e3344b0576fd619416793a31eae9c5b73bf - () https://git.kernel.org/stable/c/03505e3344b0576fd619416793a31eae9c5b73bf -
References () https://git.kernel.org/stable/c/04a4a017b9ffd7b0f427b8c376688d14cb614651 - () https://git.kernel.org/stable/c/04a4a017b9ffd7b0f427b8c376688d14cb614651 -
References () https://git.kernel.org/stable/c/1e71b6449d55179170efc8dee8664510bb813b42 - () https://git.kernel.org/stable/c/1e71b6449d55179170efc8dee8664510bb813b42 -
References () https://git.kernel.org/stable/c/3dd9be6cb55e0f47544e7cdda486413f7134e3b3 - () https://git.kernel.org/stable/c/3dd9be6cb55e0f47544e7cdda486413f7134e3b3 -
References () https://git.kernel.org/stable/c/3fe0ac10bd117df847c93408a9d428a453cd60e5 - () https://git.kernel.org/stable/c/3fe0ac10bd117df847c93408a9d428a453cd60e5 -
References () https://git.kernel.org/stable/c/6fe478d855b20ac1eb5da724afe16af5a2aaaa40 - () https://git.kernel.org/stable/c/6fe478d855b20ac1eb5da724afe16af5a2aaaa40 -
References () https://git.kernel.org/stable/c/810cd4bb53456d0503cc4e7934e063835152c1b7 - () https://git.kernel.org/stable/c/810cd4bb53456d0503cc4e7934e063835152c1b7 -
References () https://git.kernel.org/stable/c/ec73e079729258a05452356cf6d098bf1504d5a6 - () https://git.kernel.org/stable/c/ec73e079729258a05452356cf6d098bf1504d5a6 -

06 Nov 2024, 20:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.4

05 Nov 2024, 10:15

Type Values Removed Values Added
References
  • {'url': 'https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html', 'source': '416baaa9-dc9f-4396-8d5f-8c081fb06d67'}

25 Jun 2024, 21:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html -

13 Apr 2024, 12:15

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/1e71b6449d55179170efc8dee8664510bb813b42 -
  • () https://git.kernel.org/stable/c/3dd9be6cb55e0f47544e7cdda486413f7134e3b3 -

10 Apr 2024, 15:16

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se resolvió la siguiente vulnerabilidad: vfio/pci: bloquear operaciones de enmascaramiento INTx externas Las operaciones de enmascaramiento a través de cambios en el espacio de configuración a DisINTx pueden acelerar los cambios de configuración de INTx a través de ioctl. Cree contenedores que agreguen bloqueo para rutas fuera del código de interrupción central. En particular, irq_type se actualiza manteniendo igate, por lo tanto, probar is_intx() requiere mantener igate. Por ejemplo, borrar DisINTx del espacio de configuración puede acelerar los cambios en la configuración de la interrupción. Esto alinea las interfaces que pueden desencadenar el evento INTx en dos campos, un lado serializado por igate y el otro solo habilitado mientras INTx está configurado. Un parche posterior introduce la sincronización para estos últimos flujos.
References
  • () https://git.kernel.org/stable/c/ec73e079729258a05452356cf6d098bf1504d5a6 -

05 Apr 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-05 09:15

Updated : 2025-04-08 19:20


NVD link : CVE-2024-26810

Mitre link : CVE-2024-26810

CVE.ORG link : CVE-2024-26810


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')