x86/kexec: Fix bug with call depth tracking
Published Jul 12, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.24%
Description
The call to cc_platform_has() triggers a fault and system crash if call depth tracking is active because the GS segment has been reset by load_segments() and GS_BASE is now 0 but call depth tracking uses per-CPU variables to operate.
Call cc_platform_has() earlier in the function when GS is still valid.
[ bp: Massage. ]
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.2StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.2
- Version 6.10StatusunaffectedConstraints<=*
- Version 6.6.35StatusunaffectedConstraints<=6.6.*
- Version 6.9.6StatusunaffectedConstraints<=6.9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.2 · < 6.6.35
- ≥ 6.7 · < 6.9.6
- 6.10
- 6.10
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
No CWE recorded.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-40944 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297528 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-38832 Advisory
- https://git.kernel.org/stable/c/2cfb464669b645a9b98478b74f2bcea9860dcff1 Patch
- https://git.kernel.org/stable/c/93c1800b3799f17375989b0daf76497dd3e80922 Patch
- https://git.kernel.org/stable/c/d91ddd05082691e69b30744825d18ae799293258 Patch
- https://lore.kernel.org/linux-cve-announce/2024071219-CVE-2024-40944-98ef@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-40944
- https://www.cve.org/CVERecord?id=CVE-2024-40944
Change history (0)
No recorded changes yet.