Executive brief
A vulnerability was identified in the Linux kernel's Virtual Machine Communication Interface (VMCI), which facilitates communication between virtual machines and the host. A flaw in how the system handles certain data messages could allow a local user to trigger a system crash or instability. This issue primarily impacts the reliability and availability of the host system and its virtualized environments.
Technical details
A vulnerability exists in the VMCI driver (drivers/misc/vmw_vmci/vmci_datagram.c) within the dg_dispatch_as_host() function. The issue stems from a memcpy() operation that performs a field-spanning write, copying both a header and its payload into a single structure field (&dg_info->msg) instead of respecting member boundaries. Under kernels compiled with FORTIFY_SOURCE, this triggers a runtime warning and potential termination. An attacker with local access can manipulate the payload size of a VMCI datagram to trigger this out-of-bounds write behavior. The fix involves splitting the memory operation into a direct assignment for the header and a separate memcpy for the payload.
Affected products
- Linux Linux Kernel up to 4.19.312, 5.5 to 5.10.215, 6.2 to 6.6.27, 4.20 to 5.4.274, 6.7 to 6.8.6, 5.16 to 6.1.86, 5.11 to 5.15.155
Timeline
- 2024-01-05: other: Patch submitted by developer
- 2024-05-19: disclosed: Initial publication date
- 2024-04-13: patched: Commits merged into various stable branches
References
- https://git.kernel.org/stable/c/130b0cd064874e0d0f58e18fb00e6f3993e90c74
- https://git.kernel.org/stable/c/19b070fefd0d024af3daa7329cbc0d00de5302ec
- https://git.kernel.org/stable/c/491a1eb07c2bd8841d63cb5263455e185be5866f
- https://git.kernel.org/stable/c/ad78c5047dc4076d0b3c4fad4f42ffe9c86e8100
- https://git.kernel.org/stable/c/dae70a57565686f16089737adb8ac64471570f73
- https://git.kernel.org/stable/c/e87bb99d2df6512d8ee37a5d63d2ca9a39a8c051
- https://git.kernel.org/stable/c/f15eca95138b3d4ec17b63c3c1937b0aa0d3624b