CVE-2024-42135

MEDIUM

Linux Kernel < 6.6.39 - Denial of Service via vhost_task SIGKILL Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: vhost_task: Handle SIGKILL by flushing work and exiting Instead of lingering until the device is closed, this has us handle SIGKILL by: 1. marking the worker as killed so we no longer try to use it with new virtqueues and new flush operations. 2. setting the virtqueue to worker mapping so no new works are queued. 3. running all the exiting works.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (11)
linux/Kernel 6.4.0 - 6.6.39linux
linux/Kernel 6.7.0 - 6.9.9linux
Linux/Linux < 6.4
Linux/Linux 6.10
Linux/Linux 6.4
Linux/Linux 6.6.39 - 6.6.*
Linux/Linux 6.9.9 - 6.9.*
Linux/Linux f9010dbdce911ee1f1af1398a24b1f9f992e0080 - abe067dc3a662eef7d5cddbbc41ed50a0b68b0af
Linux/Linux f9010dbdce911ee1f1af1398a24b1f9f992e0080 - db5247d9bf5c6ade9fd70b4e4897441e0269b233
Linux/Linux f9010dbdce911ee1f1af1398a24b1f9f992e0080 - dec987fe2df670827eb53b97c9552ed8dfc63ad4
... and 1 more
Published Jul 30, 2024
Tracked Since Feb 18, 2026