Bug 2301500 (CVE-2024-42135)
Summary: | CVE-2024-42135 kernel: vhost_task: Handle SIGKILL by flushing work and exiting | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | dfreiber, drow, jburrell, vkumar |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | kernel 6.6.39, kernel 6.9.9, kernel 6.10 | Doc Type: | If docs needed, set a value |
Doc Text: |
A vulnerability was discovered in the Linux kernel's vhost driver where the improper handling of SIGKILL signals can leave vhost workers lingering or performing unintended operations even after receiving the kill signal. This can lead to system instability or crashes.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2301993 | ||
Bug Blocks: |
Description
OSIDB Bzimport
2024-07-30 08:36:31 UTC
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024073029-CVE-2024-42135-0694@gregkh/T Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2301993] |