Executive brief
A vulnerability in the Linux kernel's Intel i40e network driver can cause servers to hang or become unresponsive. This issue occurs during specific hardware reset conditions and affects systems using Virtual Functions (VFs) for network virtualization. An exploit could lead to a denial-of-service, impacting system availability and business operations.
Technical details
A vulnerability exists in the i40e_reset_all_vfs function within the Linux kernel's i40e driver (drivers/net/ethernet/intel/i40e/i40e_virtchnl_pf.c). The root cause is the interchangeable use of two different variables to track Virtual Function (VF) pointers, which can lead to a stale or uninitialized VF pointer being used during reset races. This race condition can cause the kernel to hang. The fix involves removing the redundant 'v' variable and using a single VF pointer for iteration to ensure validity. This is a regression of a previous fix (commit 52424f974bc5). Local access with low privileges is sufficient to trigger the condition if the attacker can influence VF reset operations.
Affected products
- Linux Linux Kernel 4.19.264 to 4.19.312, 5.4.223 to 5.4.274, 5.10.153 to 5.10.215, 5.15.77 to 5.15.154, 6.1.1 to 6.1.85, 6.2 to 6.6.26, 6.7 to 6.8.5
Timeline
- 2024-03-13: patched: Initial patch authored by Aleksandr Loktionov
- 2024-05-30: disclosed: CVE published in NVD
References
- https://git.kernel.org/stable/c/06df7618f591b2dc43c59967e294d7b9fc8675b6
- https://git.kernel.org/stable/c/0dcf573f997732702917af1563aa2493dc772fc0
- https://git.kernel.org/stable/c/3e89846283f3cf7c7a8e28b342576fd7c561d2ba
- https://git.kernel.org/stable/c/951d2748a2a8242853abc3d0c153ce4bf8faad31
- https://git.kernel.org/stable/c/9dcf0fcb80f6aeb01469e3c957f8d4c97365450a
- https://git.kernel.org/stable/c/b8e82128b44fa40bf99a50b919488ef361e1683c
- https://git.kernel.org/stable/c/cc9cd02dd9e8b7764ea9effb24f4f1dd73d1b23d