CVE-2024-44937: platform/x86: intel-vbtn: Protect ACPI notify handler against recursion
In the Linux kernel, the following vulnerability has been resolved:
platform/x86: intel-vbtn: Protect ACPI notify handler against recursion
Since commit e2ffcda16290 ("ACPI: OSL: Allow Notify () handlers to run on all CPUs") ACPI notify handlers like the intel-vbtn notifyhandler() may run on multiple CPU cores racing with themselves.
This race gets hit on Dell Venue 7140 tablets when undocking from the keyboard, causing the handler to try and register priv->switchesdev twice, as can be seen from the devinfo() message getting logged twice:
[ 83.861800] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event [ 83.861858] input: Intel Virtual Switches as /devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17 [ 83.861865] intel-vbtn INT33D6:00: Registering Intel Virtual Switches input-dev after receiving a switch event
After which things go seriously wrong: [ 83.861872] sysfs: cannot create duplicate filename '/devices/pci0000:00/0000:00:1f.0/PNP0C09:00/INT33D6:00/input/input17' ... [ 83.861967] kobject: kobjectaddinternal failed for input17 with -EEXIST, don't try to register things with the same name in the same directory. [ 83.877338] BUG: kernel NULL pointer dereference, address: 0000000000000018 ...
Protect intel-vbtn notifyhandler() from racing with itself with a mutex to fix this.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44937?
CVE-2024-44937 is considered a medium severity vulnerability in the Linux kernel.
How do I fix CVE-2024-44937?
To fix CVE-2024-44937, update to a patched version of the Linux kernel, such as 6.10.6 or newer.
Which versions of the Linux kernel are affected by CVE-2024-44937?
CVE-2024-44937 affects Linux kernel versions between 6.8 and 6.10.5, as well as 6.11-rc1 and 6.11-rc2.
What components are involved in CVE-2024-44937?
CVE-2024-44937 involves the ACPI notify handler in the Linux kernel, specifically related to the intel-vbtn driver.
Is there a known exploitation method for CVE-2024-44937?
As of now, there are no publicly disclosed exploitation methods for CVE-2024-44937.