Time-of-check Time-of-use (TOCTOU) Affecting kernel-core package, versions <0:4.18.0-372.107.1.el8_6


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.04% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-KERNELCORE-7249092
  • published12 Jun 2024
  • disclosed4 Aug 2023

Introduced: 4 Aug 2023

CVE-2023-4155  (opens in a new tab)
CWE-367  (opens in a new tab)

How to fix?

Upgrade RHEL:8 kernel-core to version 0:4.18.0-372.107.1.el8_6 or higher.
This issue was patched in RHSA-2024:3859.

NVD Description

Note: Versions mentioned in the description apply only to the upstream kernel-core package and not the kernel-core package as distributed by RHEL. See How to fix? for RHEL:8 relevant fixed versions and status.

A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the VMGEXIT handler recursively. If an attacker manages to call the handler multiple times, they can trigger a stack overflow and cause a denial of service or potentially guest-to-host escape in kernel configurations without stack guard pages (CONFIG_VMAP_STACK).

CVSS Scores

version 3.1