CVE-2024-42135

medium

Description

In the Linux kernel, the following vulnerability has been resolved: vhost_task: Handle SIGKILL by flushing work and exiting Instead of lingering until the device is closed, this has us handle SIGKILL by: 1. marking the worker as killed so we no longer try to use it with new virtqueues and new flush operations. 2. setting the virtqueue to worker mapping so no new works are queued. 3. running all the exiting works.

References

https://git.kernel.org/stable/c/dec987fe2df670827eb53b97c9552ed8dfc63ad4

https://git.kernel.org/stable/c/db5247d9bf5c6ade9fd70b4e4897441e0269b233

https://git.kernel.org/stable/c/abe067dc3a662eef7d5cddbbc41ed50a0b68b0af

Details

Source: Mitre, NVD

Published: 2024-07-30

Updated: 2024-12-11

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium