CVE-2024-36953

Aliases:UBUNTU-CVE-2024-36953DEBIAN-CVE-2024-36953
Advisory lineage Upstream: 0 Downstream: 39
Analyzed
Published: 30 May 2024, 15:35
Last modified:11 May 2026, 20:17

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.23% LOW
0% probability +0.22%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 May 2024, 15:35
Published
Vulnerability first disclosed
11 May 2026, 20:17
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU that matches the user-provided CPUID, which (of course) may not be valid. If the ID is invalid, kvm_get_vcpu_by_id() returns NULL, which isn't handled gracefully. Similar to the GICv3 uaccess flow, check that kvm_get_vcpu_by_id() actually returns something and fail the ioctl if not.

CVSS Metrics

  • v3.1MEDIUMScore: 4.4CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.23% Percentile: 14%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • debianlinux

    < 5.10.218-1 | < 6.1.94-1 | < 6.8.11-1 | < 6.8.11-1

  • ubuntulinux

    < 4.15.0-231.243 | < 5.4.0-202.222 | < 5.15.0-118.128 | < 6.8.0-40.40

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    < 4.15.0-1175.188 | < 5.4.0-1136.146 | < 5.15.0-1067.73 | < 6.8.0-1013.14

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1067.73~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1136.146~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1013.14~22.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2113.119 | all | < 5.4.0-1136.146+fips1 | < 5.15.0-1067.73+fips1

  • ubuntulinux-aws-hwe

    < 4.15.0-1175.188~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1183.198~14.04.1 | < 4.15.0-1183.198~16.04.1 | all | < 5.4.0-1142.149 | < 5.15.0-1070.79 | < 6.8.0-1012.14

  • ubuntulinux-azure-4.15

    < 4.15.0-1183.198

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1070.79~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1142.149~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1012.14~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | < 5.15.0-1070.79.1

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2092.98 | all | < 5.4.0-1142.149+fips1 | < 5.15.0-1070.79+fips1

  • ubuntulinux-bluefield

    all | < 5.4.0-1096.103 | < 5.15.0-1050.52

  • ubuntulinux-fips

    < 4.15.0-1129.140 | all | < 5.4.0-1110.120 | < 5.15.0-118.128+fips1 | < 6.8.0-78.78+fips1

  • ubuntulinux-gcp

    < 4.15.0-1168.185~16.04.1 | all | < 5.4.0-1140.149 | < 5.15.0-1066.74 | < 6.8.0-1012.13

  • ubuntulinux-gcp-4.15

    < 4.15.0-1168.185

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1066.74~20.04.1

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1140.149~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-6.2

    all

  • ubuntulinux-gcp-6.5

    all

  • ubuntulinux-gcp-6.8

    < 6.8.0-1012.13~22.04.1

  • ubuntulinux-gcp-fips

    < 4.15.0-2076.81 | all | < 5.4.0-1140.149+fips1 | < 5.15.0-1066.74+fips1

  • ubuntulinux-gke

    all | < 5.15.0-1064.70 | < 6.8.0-1008.11

Showing first 50 affected entries in server-rendered view.

References (33)