From: Vegard Nossum <vegard.nossum@oracle.com>
To: Nikolay Borisov <nik.borisov@suse.com>,
cve@kernel.org, linux-kernel@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Subject: Re: CVE-2024-35876: x86/mce: Make sure to grab mce_sysfs_mutex in set_bank()
Date: Thu, 23 May 2024 16:54:33 +0200 [thread overview]
Message-ID: <749c70b7-b405-4ce8-8418-69172c5cd515@oracle.com> (raw)
In-Reply-To: <01e1183c-46c3-41ca-8b47-d008747c164a@suse.com>
On 23/05/2024 15:58, Nikolay Borisov wrote:
> On 23.05.24 г. 16:54 ч., Vegard Nossum wrote:
>> On 23/05/2024 12:24, Nikolay Borisov wrote:
>>> I'd like to dispute the CVE for this issue. Those sysfs entries are
>>> owned by root and can only be written by it. There are innumerable
>>> ways in which root can corrupt/crash the state of the machine and I
>>> don't see why this is anything special.
>>
>> I haven't looked at the issue in detail but it sounds like this
>> potentially breaks lockdown (which is arguably a security feature) so
>
> How exactly does it break lockdown ?
Well, I don't have an exploit and it looks difficult as there isn't any
user-provided input involved.
But generally lockdown prevents anybody (including root) from inspecting
and modifying the running kernel. So if this bug would allow that, then
it breaks lockdown.
Glancing over the code it doesn't look like a use-after-free, just some
unspecified concurrent access. I can't tell if it's exploitable. I'm
just remarking that "requires root access" is not by itself a reason to
reject the CVE.
Vegard
prev parent reply other threads:[~2024-05-23 14:54 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-05-19 8:34 CVE-2024-35876: x86/mce: Make sure to grab mce_sysfs_mutex in set_bank() Greg Kroah-Hartman
2024-05-23 10:24 ` Nikolay Borisov
2024-05-23 13:32 ` Greg Kroah-Hartman
2024-05-23 13:54 ` Vegard Nossum
2024-05-23 13:58 ` Nikolay Borisov
2024-05-23 14:54 ` Vegard Nossum [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=749c70b7-b405-4ce8-8418-69172c5cd515@oracle.com \
--to=vegard.nossum@oracle.com \
--cc=cve@kernel.org \
--cc=gregkh@linuxfoundation.org \
--cc=harshit.m.mogalapalli@oracle.com \
--cc=linux-kernel@vger.kernel.org \
--cc=nik.borisov@suse.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.