Junglewise Threat Intelligence

CVE-2024-26820: Linux Kernel hv_netvsc race condition in VF registration

CVE-2024-26820 · Severity: medium · CVSS 5.5 · Published 2024-04-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Hyper-V network driver could cause network connectivity issues when the driver is reloaded. Specifically, the system may fail to properly register Virtual Functions (VF), which are used to accelerate network performance in virtualized environments. This could lead to a loss of network availability or degraded performance for affected virtual machines.

Technical details

A race condition exists in the hv_netvsc driver where the NET_DEVICE_REGISTER handler fails to register a Virtual Function (VF) if the driver is unloaded and reloaded. This occurs because the register_netdevice_notifier() is called before netvsc_probe finishes, causing the registration call to be received prematurely. An attacker with local access could potentially exploit this logic error to cause a denial of service by triggering driver reloads that result in failed network interface initialization. The fix involves explicitly checking for and registering matching VFs at the end of the netvsc_probe process.

Affected products

  • Linux Linux Kernel 4.19.301 to 4.19.310, 5.4.263 to 5.4.272, 5.10.203 to 5.10.213, 5.15.141 to 5.15.152, 6.1.65 to 6.1.79, 6.6.4 to 6.6.18, 6.7 to 6.7.6

Timeline

  • 2024-04-17: disclosed: CVE published

References

Related threats