CVE-2024-41070: KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()
In the Linux kernel, the following vulnerability has been resolved:
KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()
Al reported a possible use-after-free (UAF) in kvm_spapr_tce_attach_iommu_group().
It looks up `stt` from tablefd, but then continues to use it after doing
fdput() on the returned fd. After the fdput() the tablefd is free to be
closed by another thread. The close calls kvm_spapr_tce_release() and
then release_spapr_tce_table() (via call_rcu()) which frees `stt`.
Although there are calls to rcu_read_lock() in
kvm_spapr_tce_attach_iommu_group() they are not sufficient to prevent
the UAF, because `stt` is used outside the locked regions.
With an artifcial delay after the fdput() and a userspace program which
triggers the race, KASAN detects the UAF:
BUG: KASAN: slab-use-after-free in kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm]
Read of size 4 at addr c000200027552c30 by task kvm-vfio/2505
CPU: 54 PID: 2505 Comm: kvm-vfio Not tainted 6.10.0-rc3-next-20240612-dirty #1
Hardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV
Call Trace:
dump_stack_lvl+0xb4/0x108 (unreliable)
print_report+0x2b4/0x6ec
kasan_report+0x118/0x2b0
__asan_load4+0xb8/0xd0
kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm]
kvm_vfio_set_attr+0x524/0xac0 [kvm]
kvm_device_ioctl+0x144/0x240 [kvm]
sys_ioctl+0x62c/0x1810
system_call_exception+0x190/0x440
system_call_vectored_common+0x15c/0x2ec
...
Freed by task 0:
...
kfree+0xec/0x3e0
release_spapr_tce_table+0xd4/0x11c [kvm]
rcu_core+0x568/0x16a0
handle_softirqs+0x23c/0x920
do_softirq_own_stack+0x6c/0x90
do_softirq_own_stack+0x58/0x90
__irq_exit_rcu+0x218/0x2d0
irq_exit+0x30/0x80
arch_local_irq_restore+0x128/0x230
arch_local_irq_enable+0x1c/0x30
cpuidle_enter_state+0x134/0x5cc
cpuidle_enter+0x6c/0xb0
call_cpuidle+0x7c/0x100
do_idle+0x394/0x410
cpu_startup_entry+0x60/0x70
start_secondary+0x3fc/0x410
start_secondary_prolog+0x10/0x14
Fix it by delaying the fdput() until `stt` is no longer in use, which
is effectively the entire function. To keep the patch minimal add a call
to fdput() at each of the existing return paths. Future work can convert
the function to goto or __cleanup style cleanup.
With the fix in place the test case no longer triggers the UAF.
Security readout for executives and security teams
Plain-English summary
A race condition in Linux KVM for PowerPC can make the kernel access memory after it has been freed. A locally authenticated user able to exercise the affected virtualization path could potentially crash the host or affect confidentiality and integrity. The supplied evidence demonstrates the memory-safety failure, but not real-world exploitation.
Executive priority
Prioritize remediation on multi-user or delegated PowerPC virtualization hosts where untrusted local users can reach KVM/VFIO interfaces. Treat other systems as lower urgency after confirming the affected architecture and code path are absent. There is no supplied evidence of active exploitation.
Technical view
kvm_spapr_tce_attach_iommu_group() released a table file reference before finishing use of the associated stt object. Another thread could close the descriptor and free stt through RCU, producing a use-after-free. KASAN reproduced the race with an artificial delay. The kernel fix defers fdput() until every function exit.
Likely exposure
Exposure is limited to affected Linux kernels using KVM PPC Book3S HV and the relevant VFIO/SPAPR TCE attachment path. The supplied version data is not sufficiently clear for reliable package-level conclusions; confirm each deployed kernel against its distributor’s advisory and backport status.
Exploitation context
CVSS 3.1 rates this 7.8 with local access and low complexity, requiring low privileges and no user interaction. The source describes a purpose-built race reproducer and KASAN detection. It does not establish practical code execution or exploitation in the wild, and the bundle states this CVE is not in KEV.
Researcher notes
The demonstrated primitive is a concurrent descriptor-close race causing stt lifetime violation after fdput(). RCU read-side regions did not cover all later uses. The minimal upstream repair moves reference release to existing return paths. Source evidence supports a reproducible UAF, but does not describe exploit reliability, privilege escalation, or affected distribution package boundaries.
Mitigation direction
Install a supported vendor kernel update that incorporates the applicable stable fix.
Reboot affected hosts into the updated kernel after installation.
Prioritize PowerPC virtualization hosts using KVM, VFIO, and SPAPR TCE functionality.
If updating is delayed, consult vendor guidance for supported workload-specific mitigations.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-41070 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.