Junglewise Threat Intelligence

CVE-2024-35996: Linux Kernel CPU mitigations disabled by default on non-x86 architectures

CVE-2024-35996 · Severity: medium · CVSS 5.5 · Published 2024-05-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A configuration error in the Linux kernel caused security protections against hardware-level vulnerabilities to be disabled by default on non-x86 computer architectures (such as ARM or PowerPC). This could allow a local attacker to exploit known hardware flaws that should have been mitigated, potentially leading to system instability or unauthorized access to sensitive data. The issue has been resolved by ensuring these security mitigations are correctly enabled across all supported hardware types.

Technical details

A logic error in the Linux kernel's Kconfig files caused the 'cpu_mitigations' setting to be disabled by default for non-x86 architectures when SPECULATION_MITIGATIONS was not set. While SPECULATION_MITIGATIONS is an x86-specific toggle, the kernel-wide 'cpu_mitigations' variable is generic. This resulted in mitigations being unintentionally turned off for architectures like ARM, PowerPC, and MIPS. An attacker with local access could potentially exploit hardware vulnerabilities (such as speculative execution flaws) that would otherwise be mitigated by the kernel. The fix renames the x86-specific toggle to a generic CPU_MITIGATIONS option and ensures it defaults to enabled for all architectures.

Affected products

  • Linux Linux Kernel 5.15.156 to 5.15.158, 6.1.87 to 6.1.90, 6.6.28 to 6.6.30, 6.8.7 to 6.8.9, 6.9-rc4 to 6.9-rc5

Timeline

  • 2024-04-19: patched: Initial patch authored by Sean Christopherson
  • 2024-05-20: disclosed: CVE published

References

Related threats