CVE-2024-40989: KVM: arm64: Disassociate vcpus from redistributor region on teardown
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Disassociate vcpus from redistributor region on teardown
When tearing down a redistributor region, make sure we don't have any dangling pointer to that region stored in a vcpu.
Other sources
Linux Kernel is vulnerable to a denial of service, caused by a flaw in KVM: Arm64. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.96 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.36 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9.7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.10 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade
Linux kernel (KVM: arm64)to a version that resolves this vulnerability.Patch KVM: arm64: Disassociate vcpus from redistributor region on teardown
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40989?
CVE-2024-40989 has been classified with a high severity rating due to its potential impact on system stability and security.
How do I fix CVE-2024-40989?
To fix CVE-2024-40989, update the Linux kernel to versions 6.1.96, 6.6.36, 6.9.7, 6.10 or any appropriate patched version provided by your distribution.
What systems are affected by CVE-2024-40989?
CVE-2024-40989 affects Linux kernel versions prior to the specified remediation versions, particularly in Red Hat and Debian distributions.
What are the consequences of not addressing CVE-2024-40989?
Failing to address CVE-2024-40989 could lead to system crashes and exploitation due to dangling pointers in virtual CPUs.
Is CVE-2024-40989 specific to any architecture?
Yes, CVE-2024-40989 specifically affects the arm64 architecture within the Linux kernel.