Executive brief
A vulnerability in the Linux kernel's PCI component could allow a local user to cause a system crash (kernel oops). The issue occurs when a hardware error event (Downstream Port Containment) happens at the same time a PCI device is being physically removed or disconnected. This race condition leads to the system attempting to access memory that has already been freed, potentially impacting system stability and availability.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel's PCI Downstream Port Containment (DPC) handler. The function pci_bridge_wait_for_secondary_bus() polls the configuration space of a child device to await bus readiness after a DPC event. However, the function fails to acquire a reference count on the child pci_dev structure. If the device is hot-removed concurrently via pciehp, the dpc_handler() may attempt to access the freed struct pci_dev, resulting in a kernel oops. This issue was introduced when DPC recovery began using this function in v6.3 (and backported to v5.10+). The fix involves properly acquiring a reference using pci_dev_get() before polling and releasing it with pci_dev_put() afterward.
Affected products
- Linux Linux Kernel 5.10 to 6.10.3
Timeline
- 2024-06-18: patched: Initial patch authored by Lukas Wunner
- 2024-08-17: advisory: CVE-2024-42302 published
References
- https://git.kernel.org/stable/c/11a1f4bc47362700fcbde717292158873fb847ed
- https://git.kernel.org/stable/c/2c111413f38ca5cf87557cab89f6d82b0e3433e7
- https://git.kernel.org/stable/c/2cc8973bdc4d6c928ebe38b88090a2cdfe81f42f
- https://git.kernel.org/stable/c/b16f3ea1db47a6766a9f1169244cf1fc287a7c62
- https://git.kernel.org/stable/c/c52f9e1a9eb40f13993142c331a6cfd334d4b91d
- https://git.kernel.org/stable/c/f63df70b439bb8331358a306541893bf415bf1da
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html