LiveActive security incident?Get immediate response
CVE Record

CVE-2024-41070: KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()

In the Linux kernel, the following vulnerability has been resolved: KVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group() Al reported a possible use-after-free (UAF) in kvm_spapr_tce_attach_iommu_group(). It looks up `stt` from tablefd, but then continues to use it after doing fdput() on the returned fd. After the fdput() the tablefd is free to be closed by another thread. The close calls kvm_spapr_tce_release() and then release_spapr_tce_table() (via call_rcu()) which frees `stt`. Although there are calls to rcu_read_lock() in kvm_spapr_tce_attach_iommu_group() they are not sufficient to prevent the UAF, because `stt` is used outside the locked regions. With an artifcial delay after the fdput() and a userspace program which triggers the race, KASAN detects the UAF: BUG: KASAN: slab-use-after-free in kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm] Read of size 4 at addr c000200027552c30 by task kvm-vfio/2505 CPU: 54 PID: 2505 Comm: kvm-vfio Not tainted 6.10.0-rc3-next-20240612-dirty #1 Hardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV Call Trace: dump_stack_lvl+0xb4/0x108 (unreliable) print_report+0x2b4/0x6ec kasan_report+0x118/0x2b0 __asan_load4+0xb8/0xd0 kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm] kvm_vfio_set_attr+0x524/0xac0 [kvm] kvm_device_ioctl+0x144/0x240 [kvm] sys_ioctl+0x62c/0x1810 system_call_exception+0x190/0x440 system_call_vectored_common+0x15c/0x2ec ... Freed by task 0: ... kfree+0xec/0x3e0 release_spapr_tce_table+0xd4/0x11c [kvm] rcu_core+0x568/0x16a0 handle_softirqs+0x23c/0x920 do_softirq_own_stack+0x6c/0x90 do_softirq_own_stack+0x58/0x90 __irq_exit_rcu+0x218/0x2d0 irq_exit+0x30/0x80 arch_local_irq_restore+0x128/0x230 arch_local_irq_enable+0x1c/0x30 cpuidle_enter_state+0x134/0x5cc cpuidle_enter+0x6c/0xb0 call_cpuidle+0x7c/0x100 do_idle+0x394/0x410 cpu_startup_entry+0x60/0x70 start_secondary+0x3fc/0x410 start_secondary_prolog+0x10/0x14 Fix it by delaying the fdput() until `stt` is no longer in use, which is effectively the entire function. To keep the patch minimal add a call to fdput() at each of the existing return paths. Future work can convert the function to goto or __cleanup style cleanup. With the fix in place the test case no longer triggers the UAF.

HighCVSS 7.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A race condition in Linux KVM for PowerPC can make the kernel access memory after it has been freed. A locally authenticated user able to exercise the affected virtualization path could potentially crash the host or affect confidentiality and integrity. The supplied evidence demonstrates the memory-safety failure, but not real-world exploitation.

Executive priority

Prioritize remediation on multi-user or delegated PowerPC virtualization hosts where untrusted local users can reach KVM/VFIO interfaces. Treat other systems as lower urgency after confirming the affected architecture and code path are absent. There is no supplied evidence of active exploitation.

Technical view

kvm_spapr_tce_attach_iommu_group() released a table file reference before finishing use of the associated stt object. Another thread could close the descriptor and free stt through RCU, producing a use-after-free. KASAN reproduced the race with an artificial delay. The kernel fix defers fdput() until every function exit.

Likely exposure

Exposure is limited to affected Linux kernels using KVM PPC Book3S HV and the relevant VFIO/SPAPR TCE attachment path. The supplied version data is not sufficiently clear for reliable package-level conclusions; confirm each deployed kernel against its distributor’s advisory and backport status.

Exploitation context

CVSS 3.1 rates this 7.8 with local access and low complexity, requiring low privileges and no user interaction. The source describes a purpose-built race reproducer and KASAN detection. It does not establish practical code execution or exploitation in the wild, and the bundle states this CVE is not in KEV.

Researcher notes

The demonstrated primitive is a concurrent descriptor-close race causing stt lifetime violation after fdput(). RCU read-side regions did not cover all later uses. The minimal upstream repair moves reference release to existing return paths. Source evidence supports a reproducible UAF, but does not describe exploit reliability, privilege escalation, or affected distribution package boundaries.

Mitigation direction

  • Install a supported vendor kernel update that incorporates the applicable stable fix.
  • Reboot affected hosts into the updated kernel after installation.
  • Prioritize PowerPC virtualization hosts using KVM, VFIO, and SPAPR TCE functionality.
  • If updating is delayed, consult vendor guidance for supported workload-specific mitigations.

Validation and detection

  • Inventory PowerPC hosts and identify kernels providing KVM Book3S HV virtualization.
  • Determine whether VFIO and SPAPR TCE attachment functionality is used.
  • Compare running kernel builds with distributor advisories and backport records.
  • Confirm the active kernel after reboot contains the applicable fix.
  • Review kernel logs for KASAN, use-after-free, KVM, or unexpected host-crash indicators.
Prepared
Confidence
high
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-41070 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
2ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.8CVSS 3.1HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H1.85.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

7.8High
CVSS 3.1 vector shape for CVE-2024-41070Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux121f80ba68f1a5779a36d7b3247206e60e0a7418, 121f80ba68f1a5779a36d7b3247206e60e0a7418, 121f80ba68f1a5779a36d7b3247206e60e0a7418, 121f80ba68f1a5779a36d7b3247206e60e0a7418, 121f80ba68f1a5779a36d7b3247206e60e0a7418, 121f80ba68f1a5779a36d7b3247206e60e0a7418, 121f80ba68f1a5779a36d7b3247206e60e0a7418unaffected
LinuxLinux4.12, 0, 5.4.281, 5.10.223, 5.15.164, 6.1.101, 6.6.42, 6.9.11, 6.10affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.