CVE-2024-50114·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unregister redistributor for failed vCPU creation Alex reports that syzkaller has managed to trigger a use-after-free when tearing down a VM: BUG: KASAN: slab-use-after-free in kvm_put_kvm+0x300/0xe68 virt/kvm/kvm_main.c:5769 Read of size 8 at addr ffffff801c6890d0 by task syz.3.2219/10758 CPU: 3 UID: 0 PID: 10758 Comm: syz.3.2219 Not tainted 6.11.0-rc6-dirty #64 Hardware name: linux,dummy-virt (DT) Call trace: dump_backtrace+0x17c/0x1a8 arch/arm64/kernel/stacktrace.c:317 show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:324 __dump_stack lib/dump_stack.c:93 [inline] dump_stack_lvl+0x94/0xc0 lib/dump_stack.c:119 print_report+0x144/0x7a4 mm/kasan/report.c:377 kasan_report+0xcc/0x128 mm/kasan/report.c:601 __asan_report_load8_noabort+0x20/0x2c mm/kasan/report_generic.c:381 kvm_put_kvm+0x300/0xe68 virt/kvm/kvm_main.c:5769 kvm_vm_release+0x4c/0x60 virt/kvm/kvm_main.c:1409 __fput+0x198/0x71c fs/file_table.c:422 ____fput+0x20/0x30 fs/file_table.c:450 task_work_run+0x1cc/0x23c kernel/task_work.c:228 do_notify_resume+0x144/0x1a0 include/linux/resume_user_mode.h:50 el0_svc+0x64/0x68 arch/arm64/kernel/entry-common.c:169 el0t_64_sync_handler+0x90/0xfc arch/arm64/kernel/entry-common.c:730 el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598 Upon closer inspection, it appears that we do not properly tear down the MMIO registration for a vCPU that fails creation late in the game, e.g. a vCPU w/ the same ID already exists in the VM. It is important to consider the context of commit that introduced this bug by moving the unregistration out of __kvm_vgic_vcpu_destroy(). That change correctly sought to avoid an srcu v. config_lock inversion by breaking up the vCPU teardown into two parts, one guarded by the config_lock. Fix the use-after-free while avoiding lock inversion by adding a special-cased unregistration to __kvm_vgic_vcpu_destroy(). This is safe because failed vCPUs are torn down outside of the config_lock.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.11.6
- Published
- 2024-11-05
Affected versions
From: 6.11
Until: 6.11.6
Fixed in: 6.11.6
How to fix this CVE
Update your Linux kernel to version 6.11.6 or later to resolve a use-after-free vulnerability in ARM64 KVM vCPU creation. This vulnerability occurs when vCPU creation fails after MMIO registration, leaving dangling references that cause memory corruption during VM teardown. Apply the kernel update and reboot your system to complete the remediation.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r
- Verify if you are running ARM64 architecture: uname -m (look for 'aarch64')
- Review dmesg for KASAN errors: sudo dmesg | grep -i 'use-after-free\|KASAN'
- Check for kvm_put_kvm in kernel logs: sudo journalctl | grep -i 'kvm_put_kvm'
- Confirm the fix: After update, verify new kernel version with uname -r to ensure 6.11.6 or later
FAQ
What is CVE-2024-50114?
CVE-2024-50114 is a use-after-free vulnerability in the Linux kernel's ARM64 KVM implementation that occurs when vCPU creation fails late in the initialization process, leaving unregistered MMIO references that are accessed during VM cleanup, causing potential memory corruption and system crashes.
Is CVE-2024-50114 being actively exploited?
No, this vulnerability is not being actively exploited in the wild according to CISA's Known Exploited Vulnerabilities database, and no public exploits are currently available.
What versions of Kernel are affected by CVE-2024-50114?
Linux kernel versions 6.11 through 6.11.5 on ARM64 systems are vulnerable. The vulnerability was fixed in kernel version 6.11.6.
How do I check if my server is vulnerable to CVE-2024-50114?
Run 'uname -r' to check your kernel version and 'uname -m' to confirm you're on ARM64 (aarch64). If you see version 6.11.0 through 6.11.5 on an ARM64 system, you are vulnerable.
Does Defensia detect CVE-2024-50114?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2024-50114 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-50114. Free for 1 server.
Get started free