CVE-2024-44964·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leaks and crashes while performing a soft reset The second tagged commit introduced a UAF, as it removed restoring q_vector->vport pointers after reinitializating the structures. This is due to that all queue allocation functions are performed here with the new temporary vport structure and those functions rewrite the backpointers to the vport. Then, this new struct is freed and the pointers start leading to nowhere. But generally speaking, the current logic is very fragile. It claims to be more reliable when the system is low on memory, but in fact, it consumes two times more memory as at the moment of running this function, there are two vports allocated with their queues and vectors. Moreover, it claims to prevent the driver from running into "bad state", but in fact, any error during the rebuild leaves the old vport in the partially allocated state. Finally, if the interface is down when the function is called, it always allocates a new queue set, but when the user decides to enable the interface later on, vport_open() allocates them once again, IOW there's a clear memory leak here. Just don't allocate a new queue set when performing a reset, that solves crashes and memory leaks. Readd the old queue number and reopen the interface on rollback - that solves limbo states when the device is left disabled and/or without HW queues enabled.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.5
- Published
- 2024-09-04
Affected versions
From: 6.7
Until: 6.10.5
Fixed in: 6.10.5
How to fix this CVE
Update your Linux kernel to version 6.10.5 or later to resolve memory leaks and use-after-free crashes in the idpf driver's soft reset routine. The vulnerability stems from improper queue vector pointer restoration during device reinitialization. Apply the kernel update immediately and reboot your system to activate the patched version.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check current kernel version: uname -r
- Verify if idpf driver is loaded: lsmod | grep idpf (indicates Intel DPF network device exposure)
- Review kernel logs for crash signatures: sudo dmesg | grep -i 'UAF\|use-after-free\|idpf.*crash\|kernel panic'
- Confirm fix applied: compare uname -r output against fixed version 6.10.5; if version >= 6.10.5, vulnerability is patched
FAQ
What is CVE-2024-44964?
CVE-2024-44964 is a use-after-free vulnerability in the Linux kernel's idpf driver that occurs during soft reset operations. Improper management of queue vector backpointers and memory allocation causes kernel crashes and information disclosure when the device is reset, particularly when memory is constrained.
Is CVE-2024-44964 being actively exploited?
No, CVE-2024-44964 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available. However, as a local privilege escalation vector, it should be prioritized for patching in multi-tenant environments.
What versions of Kernel are affected by CVE-2024-44964?
Kernel versions 6.7 through 6.10.4 are vulnerable. The vulnerability was introduced in a commit that modified queue reset logic and fully resolved in kernel version 6.10.5 and later.
How do I check if my server is vulnerable to CVE-2024-44964?
Run 'uname -r' to see your kernel version. If the output shows 6.7.x through 6.10.4, your system is vulnerable. Additionally, verify idpf driver presence with 'lsmod | grep idpf' — only systems with Intel DPF network adapters can be affected.
Does Defensia detect CVE-2024-44964?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Linux kernel is installed on a monitored server, CVE-2024-44964 will appear in your dashboard with remediation steps if the version is in the vulnerable range.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-44964. Free for 1 server.
Get started free