Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-26810— vfio/pci: Lock external INTx masking ops

AI Predicted 3.3 Difficulty: Moderate EPSS 0.19% · P9

Possible ATT&CK Techniques 1AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux89e1f7d4c66d85f42c3d52ea3866eb10cadf6153< 1e71b6449d55179170efc8dee8664510bb813b42affected
89e1f7d4c66d85f42c3d52ea3866eb10cadf6153< 3dd9be6cb55e0f47544e7cdda486413f7134e3b3affected
89e1f7d4c66d85f42c3d52ea3866eb10cadf6153< ec73e079729258a05452356cf6d098bf1504d5a6affected
89e1f7d4c66d85f42c3d52ea3866eb10cadf6153< 3fe0ac10bd117df847c93408a9d428a453cd60e5affected
89e1f7d4c66d85f42c3d52ea3866eb10cadf6153< 04a4a017b9ffd7b0f427b8c376688d14cb614651affected
89e1f7d4c66d85f42c3d52ea3866eb10cadf6153< 6fe478d855b20ac1eb5da724afe16af5a2aaaa40affected
89e1f7d4c66d85f42c3d52ea3866eb10cadf6153< 03505e3344b0576fd619416793a31eae9c5b73bfaffected
89e1f7d4c66d85f42c3d52ea3866eb10cadf6153< 810cd4bb53456d0503cc4e7934e063835152c1b7affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-26810

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
vfio/pci: Lock external INTx masking ops
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Lock external INTx masking ops Mask operations through config space changes to DisINTx may race INTx configuration changes via ioctl. Create wrappers that add locking for paths outside of the core interrupt code. In particular, irq_type is updated holding igate, therefore testing is_intx() requires holding igate. For example clearing DisINTx from config space can otherwise race changes of the interrupt configuration. This aligns interfaces which may trigger the INTx eventfd into two camps, one side serialized by igate and the other only enabled while INTx is configured. A subsequent patch introduces synchronization for the latter flows.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于 vfio/pci 中存在安全问题,通过配置空间更改 DisINTx 的掩码可能会与 INTx 竞争。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 89e1f7d4c66d85f42c3d52ea3866eb10cadf6153 ~ 1e71b6449d55179170efc8dee8664510bb813b42 -
LinuxLinux 3.6 -

II. Public POCs for CVE-2024-26810

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-26810

登录查看更多情报信息。

Mailing List Discussions for CVE-2024-26810 (1)

Other References for CVE-2024-26810 (7)

Same Patch Batch · Linux · 2024-04-05 · 5 CVEs total

CVE-2024-27437vfio/pci: Disable auto-enable of exclusive INTx IRQ
CVE-2024-26814vfio/fsl-mc: Block calling interrupt handler without trigger
CVE-2024-26812vfio/pci: Create persistent INTx handler
CVE-2024-26813vfio/platform: Create persistent IRQ handlers

IV. Related Vulnerabilities

V. Comments for CVE-2024-26810

No comments yet


Leave a comment