CVE-2024-36953: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the vCPU that matches the user-provided CPUID, which (of course) may not be valid. If the ID is invalid, kvm_get_vcpu_by_id() returns NULL, which isn't handled gracefully. Similar to the GICv3 uaccess flow, check that kvm_get_vcpu_by_id() actually returns something and fail the ioctl if not.
Affected products
- Debian Debian Linux: version 10.0 only
- Linux Linux Kernel: from 4.7, before 5.10.217 (fixed in 5.10.217); from 5.11, before 5.15.159 (fixed in 5.15.159); from 5.16, before 6.1.91 (fixed in 6.1.91); from 6.2, before 6.6.31 (fixed in 6.6.31); from 6.7, before 6.8.10 (fixed in 6.8.10); version 6.9 only
Published 2024-05-30. Last modified 2026-06-17.