iommu: Return right value in iommu_sva_bind_device()
Published Jul 12, 2024
5.5
MEDIUMCVSS 3.1
EPSS 0.26%
Description
iommu_sva_bind_device() should return either a sva bond handle or an ERR_PTR value in error cases. Existing drivers (idxd and uacce) only check the return value with IS_ERR(). This could potentially lead to a kernel NULL pointer dereference issue if the function returns NULL instead of an error pointer.
In reality, this doesn't cause any problems because iommu_sva_bind_device() only returns NULL when the kernel is not configured with CONFIG_IOMMU_SVA. In this case, iommu_dev_enable_feature(dev, IOMMU_DEV_FEAT_SVA) will return an error, and the device drivers won't call iommu_sva_bind_device() at all.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.2StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.2
- Version 5.10.221StatusunaffectedConstraints<=5.10.*
- Version 5.15.162StatusunaffectedConstraints<=5.15.*
- Version 5.4.279StatusunaffectedConstraints<=5.4.*
- Version 6.1.129StatusunaffectedConstraints<=6.1.*
- Version 6.10StatusunaffectedConstraints<=*
- Version 6.6.35StatusunaffectedConstraints<=6.6.*
- Version 6.9.6StatusunaffectedConstraints<=6.9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.2 · < 5.4.279
- ≥ 5.5 · < 5.10.221
- ≥ 5.11 · < 5.15.162
- ≥ 5.16 · < 6.6.35
- ≥ 6.7 · < 6.9.6
- 6.10
- 6.10
No data.
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Fix deferred
Red Hat Enterprise Linux 8
kernel-rt
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (17)
- https://access.redhat.com/security/cve/CVE-2024-40945 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297529 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-355557.html
- https://cert-portal.siemens.com/productcert/html/ssa-613116.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-38833 Advisory
- https://git.kernel.org/stable/c/2973b8e7d127754de9013177c41c0b5547406998 Patch
- https://git.kernel.org/stable/c/61a96da9649a6b6a1a5d5bde9374b045fdb5c12e Patch
- https://git.kernel.org/stable/c/6325eab6c108fed27f60ff51852e3eac0ba23f3f
- https://git.kernel.org/stable/c/700f564758882db7c039dfba9443fe762561a3f8 Patch
- https://git.kernel.org/stable/c/7388ae6f26c0ba95f70cc96bf9c5d5cb06c908b6 Patch
- https://git.kernel.org/stable/c/89e8a2366e3bce584b6c01549d5019c5cda1205e Patch
- https://git.kernel.org/stable/c/cf34f8f66982a36e5cba0d05781b21ec9606b91e Patch
- https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html
- https://lore.kernel.org/linux-cve-announce/2024071220-CVE-2024-40945-79e6@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-40945
- https://www.cve.org/CVERecord?id=CVE-2024-40945
Change history (0)
No recorded changes yet.