Review reviewHigh

CVE-2024-26974

Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - resolve race condition during AER recovery During the PCI AER system's error recovery process, the kernel driver may encounter a race condition with freeing the reset_data structure's memory. If the device restart will take more than 10 seconds the function scheduling that restart will exit due to a timeout, and the reset_data structure will be freed. However, this data structure is used for completion notification after the restart is completed, which leads to a UAF bug. This results in a KFENCE bug notice. B...

CVSS
7
EPSS
0.20%
9.81% percentile
CISA KEV
Not listed
Published
2024.05.01
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.20%
Technical severityCVSS 7

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - resolve race condition during AER recovery During the PCI AER system's error recovery process, the kernel driver may encounter a race condition with freeing the reset_data structure's memory. If the device restart will take more than 10 seconds the function scheduling that restart will exit due to a timeout, and the reset_data structure will be freed. However, this data structure is used for completion notification after the restart is completed, which leads to a UAF bug. This results in a KFENCE bug notice. B...

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel
Affected versions
>= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < daba62d9eeddcc5b1081be7d348ca836c83c59d7, >= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < 8e81cd58aee14a470891733181a47d123193ba81, >= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < d03092550f526a79cf1ade7f0dfa74906f39eb71, >= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < 4ae5a97781ce7d6ecc9c7055396535815b64ca4f, >= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < 226fc408c5fcd23cc4186f05ea3a09a7a9aef2f7, >= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < 8a5a7611ccc7b1fba8d933a9f22a2e76859d94dc, >= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < 0c2cf5142bfb634c0ef0a1a69cdf37950747d0be, >= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < bb279ead42263e9fb09480f02a4247b2c287d828, >= d8cba25d2c68992a6e7c1d329b690a9ebe01167d < 7d42e097607c4d246d99225bf2b195b6167a210c, >= 3.17, >= 3.17 < 4.19.312, >= 4.20 < 5.4.274, >= 5.5 < 5.10.215, >= 5.11 < 5.15.154, >= 5.16 < 6.1.84, >= 6.2 < 6.6.24, >= 6.7 < 6.7.12, >= 6.8 < 6.8.3, 10.0
Fixed versions
4.19.312, 5.4.274, 5.10.215, 5.15.154, 6.1.84, 6.6.24, 6.7.12, 6.8.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-367, CWE-416