Junglewise Threat Intelligence

CVE-2024-26810: Linux kernel race condition in vfio/pci INTx masking

CVE-2024-26810 · Severity: medium · CVSS 4.4 · Published 2024-04-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's VFIO PCI driver, which is used to provide secure access to PCI devices for virtual machines and user-space drivers. A race condition in how the system handles device interrupts could allow a high-privileged local user to cause a system crash or denial-of-service. This issue primarily affects environments where hardware devices are passed through to virtualized guests.

Technical details

A race condition exists in the vfio/pci driver (specifically in `drivers/vfio/pci/vfio_pci_intrs.c`) due to improper synchronization of INTx masking operations. Mask operations performed through configuration space changes to DisINTx can race against interrupt configuration changes initiated via ioctl. The root cause is that `irq_type` updates are protected by the `igate` mutex, but certain paths testing `is_intx()` did not hold this lock. An attacker with high privileges (CAP_SYS_ADMIN or equivalent) could exploit this race to cause kernel instability or a denial-of-service. The fix introduces locking wrappers to ensure `igate` is held during external masking operations.

Affected products

  • Linux Linux kernel 3.6 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3

Timeline

  • 2024-04-05: advisory: Initial publication of the vulnerability details.
  • 2024-04-03: patched: Fixes committed to various stable kernel branches.

References

Related threats