CVE-2024-50114: KVM: arm64: Unregister redistributor for failed vCPU creation

Published Nov 5, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

KVM: arm64: Unregister redistributor for failed vCPU creation

Alex reports that syzkaller has managed to trigger a use-after-free when tearing down a VM:

BUG: KASAN: slab-use-after-free in kvmputkvm+0x300/0xe68 virt/kvm/kvmmain.c:5769 Read of size 8 at addr ffffff801c6890d0 by task syz.3.2219/10758

CPU: 3 UID: 0 PID: 10758 Comm: syz.3.2219 Not tainted 6.11.0-rc6-dirty #64 Hardware name: linux,dummy-virt (DT) Call trace: dumpbacktrace+0x17c/0x1a8 arch/arm64/kernel/stacktrace.c:317 showstack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:324 dumpstack lib/dumpstack.c:93 [inline] dumpstacklvl+0x94/0xc0 lib/dumpstack.c:119 printreport+0x144/0x7a4 mm/kasan/report.c:377 kasanreport+0xcc/0x128 mm/kasan/report.c:601 asanreportload8noabort+0x20/0x2c mm/kasan/reportgeneric.c:381 kvmputkvm+0x300/0xe68 virt/kvm/kvmmain.c:5769 kvmvmrelease+0x4c/0x60 virt/kvm/kvmmain.c:1409 fput+0x198/0x71c fs/filetable.c:422 fput+0x20/0x30 fs/filetable.c:450 taskworkrun+0x1cc/0x23c kernel/taskwork.c:228 donotifyresume+0x144/0x1a0 include/linux/resumeusermode.h:50 el0svc+0x64/0x68 arch/arm64/kernel/entry-common.c:169 el0t64synchandler+0x90/0xfc arch/arm64/kernel/entry-common.c:730 el0t64sync+0x190/0x194 arch/arm64/kernel/entry.S:598

Upon closer inspection, it appears that we do not properly tear down the MMIO registration for a vCPU that fails creation late in the game, e.g. a vCPU w/ the same ID already exists in the VM.

It is important to consider the context of commit that introduced this bug by moving the unregistration out of kvmvgicvcpudestroy(). That change correctly sought to avoid an srcu v. configlock inversion by breaking up the vCPU teardown into two parts, one guarded by the configlock.

Fix the use-after-free while avoiding lock inversion by adding a special-cased unregistration to kvmvgicvcpudestroy(). This is safe because failed vCPUs are torn down outside of the configlock.

Affected Software

6 affected componentsFixes available
Linux Linux kernel>=6.11<6.11.6
Linux Linux kernel=6.12-rc1
Linux Linux kernel=6.12-rc2
Linux Linux kernel=6.12-rc3
Linux Linux kernel=6.12-rc4
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1

Event History

Nov 5, 2024
CVE Published
via MITRE·05:10 PM
Data Sourced
via MITRE·05:10 PM
DescriptionSeverity
Mar 28, 2025
Data Sourced
via Ubuntu·12:57 AM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-50114?

CVE-2024-50114 is classified as a use-after-free vulnerability in the Linux kernel affecting KVM on arm64.

2

How do I fix CVE-2024-50114?

To address CVE-2024-50114, upgrade the Linux kernel to versions 6.11.6 or later, or to 6.12-rc1 or later.

3

Which versions of the Linux kernel are affected by CVE-2024-50114?

CVE-2024-50114 affects Linux kernel versions from 6.11 up to 6.11.6, as well as versions 6.12-rc1, 6.12-rc2, 6.12-rc3, and 6.12-rc4.

4

What is the impact of CVE-2024-50114?

The impact of CVE-2024-50114 can lead to potential denial of service or arbitrary code execution due to the use-after-free condition.

5

Who reported CVE-2024-50114?

CVE-2024-50114 was reported by a security researcher named Alex, who utilized syzkaller to trigger the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203