Junglewise Threat Intelligence

CVE-2024-47730: Linux Kernel HiSilicon QM use-after-free in crypto driver

CVE-2024-47730 · Severity: high · CVSS 7.8 · Published 2024-10-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's HiSilicon crypto driver could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system handles memory errors in the hardware accelerator; if handled in the wrong order, the device may attempt to access memory that has already been released. This could lead to data corruption or a complete system failure in environments using HiSilicon hardware acceleration.

Technical details

A use-after-free (UAF) vulnerability exists in the drivers/crypto/hisilicon/qm.c component of the Linux kernel. When an accelerator core reports a memory error, the driver must inject a Queue Manager (QM) error to close the 'master ooo' (out-of-order) state. Previously, this injection occurred after the queue was stopped and its associated memory was released, leading to a race condition where the hardware device could access freed memory. The fix reorders these operations to ensure the master ooo is closed before memory is released. This vulnerability is reachable by a local user with sufficient privileges to trigger or interact with the crypto hardware reset prepare path.

Affected products

  • Linux Linux Kernel 5.8 to 5.10.235, 5.11 to 5.15.174, 5.16 to 6.1.113, 6.2 to 6.6.54, 6.7 to 6.10.13, 6.11 to 6.11.2

Timeline

  • 2024-10-21: disclosed: Initial disclosure and patch release in stable kernels
  • 2024-10-21: advisory: CVE-2024-47730 assigned

References

Related threats