Improper error handling in Linux kernel - CVE-2024-41008

 

Improper error handling in Linux kernel - CVE-2024-41008

Published: July 17, 2024


Vulnerability identifier: #VU94462
CSH Severity: Low
CVSS v4 BT: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2024-41008
CWE-ID: CWE-388
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling within the kfd_smi_event_update_thermal_throttling() function in drivers/gpu/drm/amd/amdkfd/kfd_smi_events.c, within the sdma_v4_4_2_print_iv_entry() function in drivers/gpu/drm/amd/amdgpu/sdma_v4_4_2.c, within the sdma_v4_0_print_iv_entry() function in drivers/gpu/drm/amd/amdgpu/sdma_v4_0.c, within the gmc_v9_0_process_interrupt() function in drivers/gpu/drm/amd/amdgpu/gmc_v9_0.c, within the gmc_v8_0_process_interrupt() function in drivers/gpu/drm/amd/amdgpu/gmc_v8_0.c, within the gmc_v11_0_process_interrupt() function in drivers/gpu/drm/amd/amdgpu/gmc_v11_0.c, within the gmc_v10_0_process_interrupt() function in drivers/gpu/drm/amd/amdgpu/gmc_v10_0.c, within the amdgpu_vm_ptes_update() function in drivers/gpu/drm/amd/amdgpu/amdgpu_vm_pt.c, within the amdgpu_vm_validate(), amdgpu_vm_wait_idle(), amdgpu_vm_init(), amdgpu_vm_fini() and amdgpu_vm_ioctl() functions in drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c, within the amdgpu_coredump() function in drivers/gpu/drm/amd/amdgpu/amdgpu_reset.c, within the amdgpu_job_timedout() function in drivers/gpu/drm/amd/amdgpu/amdgpu_job.c, within the amdgpu_gem_object_open() function in drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c, within the amdgpu_debugfs_vm_info_show() function in drivers/gpu/drm/amd/amdgpu/amdgpu_debugfs.c. A local user can perform a denial of service (DoS) attack.


Affected software

Linux kernel
Oracle Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Anolis OS
openEuler
ThinkSystem SR655 V3
ThinkStation P520 Workstation
ThinkStation P520c Workstation
ThinkStation P620 Workstation
ThinkStation P720 Workstation
ThinkStation P920 Workstation
ThinkSystem SR650 V2
ThinkSystem SR650 V3
ThinkSystem SR655
ThinkStation P358 Workstation
ThinkSystem SR665
ThinkSystem SR665 V3
ThinkSystem SR670 V2
ThinkSystem SR675 V3
ThinkSystem SR685a V3
ThinkSystem SR850 V3
ThinkSystem SR860 V3
ThinkStation P350 Workstation
ThinkStation P340 Workstation
PowerEdge XE9680
PowerEdge R750XA
PowerEdge R760xa
PowerEdge R7625
PowerEdge R7615
AMD Graphics Processing Unit (GPU) Adapter Linux Driver
AMD Graphics Driver for Linux®
PowerEdge R7525
PowerEdge R7515
OpenShift Logging
Cloud Pak for Network Automation
Technical Support Appliance
IBM Cloud Pak for Watson AIOps
Guardium Data Protection
Red Hat OpenShift Container Platform
kernel (Red Hat package)
kernel-rt (Red Hat package)
kernel-devel
kernel-doc
kernel-abi-stablelists
python3-perf
perf
kernel-tools-libs-devel
kernel-tools-libs
kernel-tools
kernel-modules-extra
kernel-modules
bpftool
kernel
kernel-core
kernel-cross-headers
kernel-debug
kernel-debug-core
kernel-debug-devel
kernel-debug-modules
kernel-debug-modules-extra
kernel-headers
kernel-debuginfo
python3-perf-debuginfo
perf-debuginfo
kernel-tools-devel
kernel-tools-debuginfo
kernel-source
kernel-debugsource
bpftool-debuginfo

How to mitigate CVE-2024-41008

Install update from vendor's website.

PowerEdge XE9680 - update to A00
AMD Graphics Processing Unit (GPU) Adapter Linux Driver - update to ROCM 6.2.0
PowerEdge R750XA - update to 1.0
PowerEdge R760xa - update to 1.0
PowerEdge R7525 - update to 1.0
PowerEdge R7515 - update to 1.0
PowerEdge R7625 - update to 1.0
PowerEdge R7615 - update to 1.0
Cloud Pak for Network Automation - update to 2.7.7
Technical Support Appliance - update to 3.0.1
IBM Cloud Pak for Watson AIOps - update to 4.7.0
Red Hat OpenShift Container Platform - addressed in versions 4.13.52, 4.14.38, 4.15.35, 4.16.25, 4.17.7
kernel (Red Hat package) - addressed in versions 4.18.0-553.22.1.el8_10, 5.14.0-427.47.1.el9_4
kernel-rt (Red Hat package) - update to 4.18.0-553.22.1.rt7.363.el8_10
kernel-devel - update to 4.18.0-553.22.1.0.1
kernel-doc - update to 4.18.0-553.22.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.22.1.0.1
python3-perf - update to 4.18.0-553.22.1.0.1
perf - update to 4.18.0-553.22.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.22.1.0.1
kernel-tools-libs - update to 4.18.0-553.22.1.0.1
kernel-tools - update to 4.18.0-553.22.1.0.1
kernel-modules-extra - update to 4.18.0-553.22.1.0.1
kernel-modules - update to 4.18.0-553.22.1.0.1
bpftool - update to 4.18.0-553.22.1.0.1
kernel - update to 4.18.0-553.22.1.0.1
kernel-core - update to 4.18.0-553.22.1.0.1
kernel-cross-headers - update to 4.18.0-553.22.1.0.1
kernel-debug - update to 4.18.0-553.22.1.0.1
kernel-debug-core - update to 4.18.0-553.22.1.0.1
kernel-debug-devel - update to 4.18.0-553.22.1.0.1
kernel-debug-modules - update to 4.18.0-553.22.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.22.1.0.1
kernel-headers - update to 4.18.0-553.22.1.0.1
OpenShift Logging - update to 5.6.25
kernel-debuginfo - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
kernel - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
python3-perf-debuginfo - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
python3-perf - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
perf-debuginfo - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
perf - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
kernel-tools-devel - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
kernel-tools-debuginfo - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
kernel-tools - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
kernel-source - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
kernel-headers - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
kernel-devel - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
kernel-debugsource - addressed in versions 5.10.0-136.92.0.173, 5.10.0-226.0.0.125, 5.10.0-226.0.0.129, 6.6.0-44.0.0.50
bpftool-debuginfo - addressed in versions 5.10.0-226.0.0.125, 6.6.0-44.0.0.50
bpftool - addressed in versions 5.10.0-226.0.0.125, 6.6.0-44.0.0.50
Guardium Data Protection - addressed in versions 12.0p35, 12.0p115
AMD Graphics Driver for Linux® - update to 24.30.2

External References

Related Security Bulletins