CVE-2024-42135
MEDIUMLinux Kernel < 6.6.39 - Denial of Service via vhost_task SIGKILL Handling
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: vhost_task: Handle SIGKILL by flushing work and exiting Instead of lingering until the device is closed, this has us handle SIGKILL by: 1. marking the worker as killed so we no longer try to use it with new virtqueues and new flush operations. 2. setting the virtqueue to worker mapping so no new works are queued. 3. running all the exiting works.
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0023
EPSS Percentile
13.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (11)
linux/Kernel
6.4.0 - 6.6.39linux
linux/Kernel
6.7.0 - 6.9.9linux
Linux/Linux
< 6.4
Linux/Linux
6.10
Linux/Linux
6.4
Linux/Linux
6.6.39 - 6.6.*
Linux/Linux
6.9.9 - 6.9.*
Linux/Linux
f9010dbdce911ee1f1af1398a24b1f9f992e0080 - abe067dc3a662eef7d5cddbbc41ed50a0b68b0af
Linux/Linux
f9010dbdce911ee1f1af1398a24b1f9f992e0080 - db5247d9bf5c6ade9fd70b4e4897441e0269b233
Linux/Linux
f9010dbdce911ee1f1af1398a24b1f9f992e0080 - dec987fe2df670827eb53b97c9552ed8dfc63ad4
... and 1 more
Published
Jul 30, 2024
Tracked Since
Feb 18, 2026