Junglewise Threat Intelligence

CVE-2024-35944: Linux Kernel VMCI field-spanning write in dg_dispatch_as_host

CVE-2024-35944 · Severity: medium · CVSS 5.5 · Published 2024-05-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Virtual Machine Communication Interface (VMCI), which facilitates communication between virtual machines and the host. A flaw in how the system handles certain data messages could allow a local user to trigger a system crash or instability. This issue primarily impacts the reliability and availability of the host system and its virtualized environments.

Technical details

A vulnerability exists in the VMCI driver (drivers/misc/vmw_vmci/vmci_datagram.c) within the dg_dispatch_as_host() function. The issue stems from a memcpy() operation that performs a field-spanning write, copying both a header and its payload into a single structure field (&dg_info->msg) instead of respecting member boundaries. Under kernels compiled with FORTIFY_SOURCE, this triggers a runtime warning and potential termination. An attacker with local access can manipulate the payload size of a VMCI datagram to trigger this out-of-bounds write behavior. The fix involves splitting the memory operation into a direct assignment for the header and a separate memcpy for the payload.

Affected products

  • Linux Linux Kernel up to 4.19.312, 5.5 to 5.10.215, 6.2 to 6.6.27, 4.20 to 5.4.274, 6.7 to 6.8.6, 5.16 to 6.1.86, 5.11 to 5.15.155

Timeline

  • 2024-01-05: other: Patch submitted by developer
  • 2024-05-19: disclosed: Initial publication date
  • 2024-04-13: patched: Commits merged into various stable branches

References

Related threats