Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-42134
HistoryJul 30, 2024 - 12:00 a.m.

CVE-2024-42134

2024-07-3000:00:00
ubuntu.com
ubuntu.com
3
linux kernel
vulnerability
virtio-pci
vp_del_vqs function
null check
patch
virsh attach device

AI Score

7

Confidence

High

In the Linux kernel, the following vulnerability has been resolved:
virtio-pci: Check if is_avq is NULL
[bug]
In the virtio_pci_common.c function vp_del_vqs, vp_dev->is_avq is involved
to determine whether it is admin virtqueue, but this function
vp_dev->is_avq
may be empty. For installations, virtio_pci_legacy does not assign a value
to vp_dev->is_avq.
[fix]
Check whether it is vp_dev->is_avq before use.
[test]
Test with virsh Attach device
Before this patch, the following command would crash the guest system
After applying the patch, everything seems to be working fine.