CVE-2024-50114: KVM: arm64: Unregister redistributor for failed vCPU creation
In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: Unregister redistributor for failed vCPU creation
Alex reports that syzkaller has managed to trigger a use-after-free when tearing down a VM:
BUG: KASAN: slab-use-after-free in kvmputkvm+0x300/0xe68 virt/kvm/kvmmain.c:5769 Read of size 8 at addr ffffff801c6890d0 by task syz.3.2219/10758
CPU: 3 UID: 0 PID: 10758 Comm: syz.3.2219 Not tainted 6.11.0-rc6-dirty #64 Hardware name: linux,dummy-virt (DT) Call trace: dumpbacktrace+0x17c/0x1a8 arch/arm64/kernel/stacktrace.c:317 showstack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:324 dumpstack lib/dumpstack.c:93 [inline] dumpstacklvl+0x94/0xc0 lib/dumpstack.c:119 printreport+0x144/0x7a4 mm/kasan/report.c:377 kasanreport+0xcc/0x128 mm/kasan/report.c:601 asanreportload8noabort+0x20/0x2c mm/kasan/reportgeneric.c:381 kvmputkvm+0x300/0xe68 virt/kvm/kvmmain.c:5769 kvmvmrelease+0x4c/0x60 virt/kvm/kvmmain.c:1409 fput+0x198/0x71c fs/filetable.c:422 fput+0x20/0x30 fs/filetable.c:450 taskworkrun+0x1cc/0x23c kernel/taskwork.c:228 donotifyresume+0x144/0x1a0 include/linux/resumeusermode.h:50 el0svc+0x64/0x68 arch/arm64/kernel/entry-common.c:169 el0t64synchandler+0x90/0xfc arch/arm64/kernel/entry-common.c:730 el0t64sync+0x190/0x194 arch/arm64/kernel/entry.S:598
Upon closer inspection, it appears that we do not properly tear down the MMIO registration for a vCPU that fails creation late in the game, e.g. a vCPU w/ the same ID already exists in the VM.
It is important to consider the context of commit that introduced this bug by moving the unregistration out of kvmvgicvcpudestroy(). That change correctly sought to avoid an srcu v. configlock inversion by breaking up the vCPU teardown into two parts, one guarded by the configlock.
Fix the use-after-free while avoiding lock inversion by adding a special-cased unregistration to kvmvgicvcpudestroy(). This is safe because failed vCPUs are torn down outside of the configlock.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50114?
CVE-2024-50114 is classified as a use-after-free vulnerability in the Linux kernel affecting KVM on arm64.
How do I fix CVE-2024-50114?
To address CVE-2024-50114, upgrade the Linux kernel to versions 6.11.6 or later, or to 6.12-rc1 or later.
Which versions of the Linux kernel are affected by CVE-2024-50114?
CVE-2024-50114 affects Linux kernel versions from 6.11 up to 6.11.6, as well as versions 6.12-rc1, 6.12-rc2, 6.12-rc3, and 6.12-rc4.
What is the impact of CVE-2024-50114?
The impact of CVE-2024-50114 can lead to potential denial of service or arbitrary code execution due to the use-after-free condition.
Who reported CVE-2024-50114?
CVE-2024-50114 was reported by a security researcher named Alex, who utilized syzkaller to trigger the vulnerability.