CVE-2024-31852: Medium severity llvm llvm vulnerability

Published Apr 5, 2024
·
Updated

LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack and thus there can sometimes be an exploitable error in the flow of control. This affects the ARM backend and can be demonstrated with Clang. NOTE: the vendor perspective is "we don't have strong objections for a CVE to be created ... It does seem that the likelihood of this miscompile enabling an exploit remains very low because the miscompile resulting in this JOP gadget is such that the function is most likely to crash on most valid inputs to the function. So if this function is covered by any testing the miscompile is most likely to be discovered before the binary is shipped to production."

Other sources

LLVM before 18.1.3 generates code in which the LR register can be overwritten without data being saved to the stack, and thus there can sometimes be an exploitable error in the flow of control. This affects the ARM backend and can be demonstrated with Clang. NOTE: the vendor perspective is "we don't have strong objections for a CVE to be created ... It does seem that the likelihood of this miscompile enabling an exploit remains very low, because the miscompile resulting in this JOP gadget is such that the function is most likely to crash on most valid inputs to the function. So, if this function is covered by any testing, the miscompile is most likely to be discovered before the binary is shipped to production."

MITRE

Affected Software

17 affected componentsFixes available
llvm llvm<18.1.3
Clang Clang<18.1.3
Microsoft azl3 compiler-rt 18.1.2-3<18.1.2-2
18.1.2-2
Microsoft azl3 clang 18.1.2-4<18.1.2-2
18.1.2-2
Microsoft azl3 rust 1.75.0-14<1.75.0-9
1.75.0-9
Microsoft cbl2 rust 1.72.0-10<1.72.0-8
1.72.0-8
Microsoft azl3 llvm 18.1.2-4<18.1.2-3
18.1.2-3
Microsoft azl3 lld 18.1.2-2<18.1.2-2
18.1.2-2
Microsoft azl3 rust 1.86.0-1
Microsoft azl3 lld 18.1.2-3<18.1.2-2
18.1.2-2
Microsoft azl3 llvm 18.1.2-3<18.1.2-3
18.1.2-3
Microsoft azl3 lldb 18.1.2-2<18.1.2-2
18.1.2-2
Microsoft azl3 libcxx 18.1.2-3<18.1.2-3
18.1.2-3
Microsoft azl3 compiler-rt 18.1.2-2<18.1.2-2
18.1.2-2
Microsoft azl3 rust 1.75.0-9<1.75.0-9
1.75.0-9
Microsoft cbl2 clang16 16.0.0-1<16.0.0-1
16.0.0-1
Microsoft cbl2 rust 1.72.0-8<1.72.0-8
1.72.0-8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.75.0-9
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.1.2-2
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.1.2-3
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.72.0-8
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 16.0.0-1
  6. Upgrade

    Upgrade LLVM/Clang (ARM backend) to a version that resolves this vulnerability.

    Fixed in 18.1.3

Event History

Apr 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverity
Jun 30, 2024
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
SeverityAffected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-31852?

CVE-2024-31852 is considered a critical vulnerability due to the potential for control flow errors that may lead to exploitability.

2

How do I fix CVE-2024-31852?

To mitigate CVE-2024-31852, update LLVM and Clang to version 18.1.3 or later.

3

Which versions of LLVM are affected by CVE-2024-31852?

CVE-2024-31852 affects all versions of LLVM prior to 18.1.3.

4

Are there any specific platforms affected by CVE-2024-31852?

CVE-2024-31852 impacts the ARM backend of LLVM and Clang.

5

What type of systems are vulnerable to CVE-2024-31852?

Systems utilizing LLVM or Clang versions before 18.1.3, specifically on ARM architectures, are vulnerable to CVE-2024-31852.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203