CVE-2024-42135
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/07/2024
Last modified:
11/12/2024
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
vhost_task: Handle SIGKILL by flushing work and exiting<br />
<br />
Instead of lingering until the device is closed, this has us handle<br />
SIGKILL by:<br />
<br />
1. marking the worker as killed so we no longer try to use it with<br />
new virtqueues and new flush operations.<br />
2. setting the virtqueue to worker mapping so no new works are queued.<br />
3. running all the exiting works.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.39 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.9.9 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/abe067dc3a662eef7d5cddbbc41ed50a0b68b0af
- https://git.kernel.org/stable/c/db5247d9bf5c6ade9fd70b4e4897441e0269b233
- https://git.kernel.org/stable/c/dec987fe2df670827eb53b97c9552ed8dfc63ad4
- https://git.kernel.org/stable/c/abe067dc3a662eef7d5cddbbc41ed50a0b68b0af
- https://git.kernel.org/stable/c/db5247d9bf5c6ade9fd70b4e4897441e0269b233
- https://git.kernel.org/stable/c/dec987fe2df670827eb53b97c9552ed8dfc63ad4



