CVE-2024-26812: vfio/pci: Create persistent INTx handler

Published Apr 5, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

vfio/pci: Create persistent INTx handler

A vulnerability exists where the eventfd for INTx signaling can be deconfigured, which unregisters the IRQ handler but still allows eventfds to be signaled with a NULL context through the SETIRQS ioctl or through unmask irqfd if the device interrupt is pending.

Ideally this could be solved with some additional locking; the igate mutex serializes the ioctl and config space accesses, and the interrupt handler is unregistered relative to the trigger, but the irqfd path runs asynchronous to those. The igate mutex cannot be acquired from the atomic context of the eventfd wake function. Disabling the irqfd relative to the eventfd registration is potentially incompatible with existing userspace.

As a result, the solution implemented here moves configuration of the INTx interrupt handler to track the lifetime of the INTx context object and irqtype configuration, rather than registration of a particular trigger eventfd. Synchronization is added between the ioctl path and eventfdsignal() wrapper such that the eventfd trigger can be dynamically updated relative to in-flight interrupts or irqfd callbacks.

Other sources

In the Linux kernel, the following vulnerability has been resolved:

vfio/pci: Create persistent INTx handler

The Linux kernel CVE team has assigned CVE-2024-26812 to this issue.

Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024040550-CVE-2024-26812-1e08@gregkh/T

Red Hat

Affected Software

14 affected componentsFixes available
Linux Linux kernel>=3.6<6.1.84
Linux Linux kernel>=6.2<6.6.24
Linux Linux kernel>=6.7<6.7.12
Linux Linux kernel>=6.8<6.8.3
Debian Debian Linux=10.0
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
redhat/kernel<6.1.84
6.1.84
redhat/kernel<6.6.24
6.6.24
redhat/kernel<6.7.12
6.7.12
redhat/kernel<6.8.3
6.8.3
redhat/kernel<6.9
6.9
Microsoft cbl2 kernel 5.15.182.1-1
Microsoft cbl2 kernel 5.15.176.3-3<5.15.176.3-3
5.15.176.3-3
Microsoft cbl2 kernel 5.15.182.1-1<5.15.176.3-3
5.15.176.3-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
  2. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 6.1.84
  3. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 6.6.24
  4. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 6.7.12
  5. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 6.8.3
  6. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 6.9
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 5.15.176.3-3
  8. Upgrade

    Upgrade Linux kernel vfio/pci INTx handler to a version that resolves this vulnerability.

    Patch CVE-2024-26812

Event History

Apr 5, 2024
CVE Published
via MITRE·08:24 AM
Data Sourced
via MITRE·08:24 AM
DescriptionSeverity
Data Sourced
via NVD·09:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·01:12 PM
DescriptionSeverityAffected Software
Jun 8, 2024
Data Sourced
via Launchpad·12:59 AM
Description
Apr 28, 2025
Data Sourced
via Ubuntu·02:20 PM
RemedyDescriptionSeverityAffected Software
Sep 4, 2025
Data Sourced
via Microsoft·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:30 AM
Affected Software
Updated
via Microsoft·08:30 AM
DescriptionSeverity
Updated
via Microsoft·08:30 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2024-26812?

CVE-2024-26812 has been classified as a medium severity vulnerability in the Linux kernel.

2

How do I fix CVE-2024-26812?

To remediate CVE-2024-26812, update your Linux kernel to versions 6.1.84 or newer, or 5.10.223-1 or newer for Debian systems.

3

What impact does CVE-2024-26812 have on system security?

CVE-2024-26812 can lead to deregistration of the IRQ handler while allowing signaling, which may result in unexpected behavior or privilege escalation.

4

Which Linux kernel versions are affected by CVE-2024-26812?

CVE-2024-26812 affects multiple kernel versions prior to 6.1.84, 6.6.24, 6.7.12, 6.8.3, and 6.9.

5

Is CVE-2024-26812 present in earlier Debian kernels?

Yes, CVE-2024-26812 is present in earlier Debian kernels before the fixed versions 5.10.223-1 and 6.1.123-1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203