CVE-2024-46824: iommufd: Require drivers to supply the cache_invalidate_user ops

Published Sep 27, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Require drivers to supply the cacheinvalidateuser ops

If drivers don't do this then iommufd will oops invalidation ioctls with something like:

Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 Mem abort info: ESR = 0x0000000086000004 EC = 0x21: IABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault user pgtable: 4k pages, 48-bit VAs, pgdp=0000000101059000 [0000000000000000] pgd=0000000000000000, p4d=0000000000000000 Internal error: Oops: 0000000086000004 [#1] PREEMPT SMP Modules linked in: CPU: 2 PID: 371 Comm: qemu-system-aar Not tainted 6.8.0-rc7-gde77230ac23a #9 Hardware name: linux,dummy-virt (DT) pstate: 81400809 (Nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=-c) pc : 0x0 lr : iommufdhwptinvalidate+0xa4/0x204 sp : ffff800080f3bcc0 x29: ffff800080f3bcf0 x28: ffff0000c369b300 x27: 0000000000000000 x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000 x23: 0000000000000000 x22: 00000000c1e334a0 x21: ffff0000c1e334a0 x20: ffff800080f3bd38 x19: ffff800080f3bd58 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: 0000ffff8240d6d8 x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000 x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000 x8 : 0000001000000002 x7 : 0000fffeac1ec950 x6 : 0000000000000000 x5 : ffff800080f3bd78 x4 : 0000000000000003 x3 : 0000000000000002 x2 : 0000000000000000 x1 : ffff800080f3bcc8 x0 : ffff0000c6034d80 Call trace: 0x0 iommufdfopsioctl+0x154/0x274 arm64sysioctl+0xac/0xf0 invokesyscall+0x48/0x110 el0svccommon.constprop.0+0x40/0xe0 doel0svc+0x1c/0x28 el0svc+0x34/0xb4 el0t64synchandler+0x120/0x12c el0t64sync+0x190/0x194

All existing drivers implement this op for nesting, this is mostly a bisection aid.

Other sources

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

2 affected componentsFixes available
Linux Linux kernel>=6.8<6.10.10
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1

Event History

Sep 27, 2024
CVE Published
via MITRE·12:39 PM
Data Sourced
via MITRE·12:39 PM
Description
Data Sourced
via Red Hat·01:21 PM
DescriptionSeverityAffected Software
Dec 12, 2024
Data Sourced
via Launchpad·06:26 PM
Description
Jan 9, 2025
Data Sourced
via Ubuntu·06:32 PM
RemedyDescriptionSeverityAffected Software
Apr 3, 2025
Data Sourced
via Debian·08:51 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-46824?

CVE-2024-46824 has a medium severity rating due to its potential to cause kernel crashes and instability in affected systems.

2

How do I fix CVE-2024-46824?

To fix CVE-2024-46824, update the Linux kernel to a version that includes the patch, such as versions 5.10.223-1, 5.10.226-1, 6.1.123-1, or 6.12.11-1.

3

Which Linux kernel versions are affected by CVE-2024-46824?

CVE-2024-46824 affects Linux kernel versions from 6.8 to 6.10.10.

4

Can CVE-2024-46824 lead to system crashes?

Yes, CVE-2024-46824 can cause kernel oops and crashes if the required cache_invalidate_user operations are not supplied by drivers.

5

Is there a specific configuration needed to mitigate CVE-2024-46824?

No specific configuration is necessary apart from ensuring that your system is updated to include the patched kernel version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203