<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 04:41:20 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-55916 — Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-55916</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet&lt;/p&gt;
&lt;p&gt;If the KVP (or VSS) daemon starts before the VMBus channel&amp;#39;s ringbuffer is
fully initialized, we can hit the panic below:&lt;/p&gt;
&lt;p&gt;hv_utils: Registering HyperV Utility Driver
hv_vmbus: registering driver hv_utils
...
BUG: kernel NULL pointer dereference, address: 0000000000000000
CPU: 44 UID: 0 PID: 2552 Comm: hv_kvp_daemon Tainted: G E 6.11.0-rc3+ #1
RIP: 0010:hv_pkt_iter_first+0x12/0xd0
Call Trace:
...
 vmbus_recvpacket
 hv_kvp_onchannelcallback
 vmbus_on_event
 tasklet_action_common
 tasklet_action
 handle_softirqs
 irq_exit_rcu
 sysvec_hyperv_stimer0
 &amp;lt;/IRQ&amp;gt;
 &amp;lt;TASK&amp;gt;
 asm_sysvec_hyperv_stimer0
...
 kvp_register_done
 hvt_op_read
 vfs_read
 ksys_read
 __x64_sys_read&lt;/p&gt;
&lt;p&gt;This can happen because the KVP/VSS channel callback can be invoked
even before the channel is fully opened:
1) as soon as hv_kvp_init() -&amp;gt; hvutil_transport_init() creates
/dev/vmbus/hv_kvp, the kvp daemon can open the device file immediately and
register itself to the driver by writing a message KVP_OP_REGISTER1 to the
file (which is handled by kvp_on_msg() -&amp;gt;kvp_handle_handshake()) and
reading the file for the driver&amp;#39;s response, which is handled by
hvt_op_read(), which calls hvt-&amp;gt;on_read(), i.e. kvp_register_done().&lt;/p&gt;
&lt;p&gt;2) the problem with kvp_register_done() is that it can cause the
channel callback to be called even before the channel is fully opened,
and when the channel callback…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet&lt;/p&gt;
&lt;p&gt;If the KVP (or VSS) daemon starts before the VMBus channel&amp;#39;s ringbuffer is
fully initialized, we can hit the panic below:&lt;/p&gt;
&lt;p&gt;hv_utils: Registering HyperV Utility Driver
hv_vmbus: registering driver hv_utils
...
BUG: kernel NULL pointer dereference, address: 0000000000000000
CPU: 44 UID: 0 PID: 2552 Comm: hv_kvp_daemon Tainted: G E 6.11.0-rc3+ #1
RIP: 0010:hv_pkt_iter_first+0x12/0xd0
Call Trace:
...
 vmbus_recvpacket
 hv_kvp_onchannelcallback
 vmbus_on_event
 tasklet_action_common
 tasklet_action
 handle_softirqs
 irq_exit_rcu
 sysvec_hyperv_stimer0
 &amp;lt;/IRQ&amp;gt;
 &amp;lt;TASK&amp;gt;
 asm_sysvec_hyperv_stimer0
...
 kvp_register_done
 hvt_op_read
 vfs_read
 ksys_read
 __x64_sys_read&lt;/p&gt;
&lt;p&gt;This can happen because the KVP/VSS channel callback can be invoked
even before the channel is fully opened:
1) as soon as hv_kvp_init() -&amp;gt; hvutil_transport_init() creates
/dev/vmbus/hv_kvp, the kvp daemon can open the device file immediately and
register itself to the driver by writing a message KVP_OP_REGISTER1 to the
file (which is handled by kvp_on_msg() -&amp;gt;kvp_handle_handshake()) and
reading the file for the driver&amp;#39;s response, which is handled by
hvt_op_read(), which calls hvt-&amp;gt;on_read(), i.e. kvp_register_done().&lt;/p&gt;
&lt;p&gt;2) the problem with kvp_register_done() is that it can cause the
channel callback to be called even before the channel is fully opened,
and when the channel callback…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-55916</guid>
    </item>
  </channel>
</rss>
