🛡️ AZL-42100 — hyperv-daemons (CVE-2024-35854)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2024-35854 affecting package hyperv-daemons for versions less than 6.6.35.1-1

In the Linux kernel, the following vulnerability has been resolved:

mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash

The rehash delayed work migrates filters from one region to another

according to the number of available credits.

The migrated from region is destroyed at the end of the work if the

number of credits is non-negative as the assumption is that this is

indicative of migration being complete. This assumption is incorrect as

a non-negative number of credits can also be the result of a failed

migration.

The destruction of a region that still has filters referencing it can

result in a use-after-free [1].

Fix by not destroying the region if migration failed.

[1]

BUG: KASAN: slab-use-after-free in mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230

Read of size 8 at addr ffff8881735319e8 by task kworker/0:31/3858

CPU: 0 PID: 3858 Comm: kworker/0:31 Tainted: G W 6.9.0-rc2-custom-00782-gf2275c2157d8 #5

Hardware name: Mellanox Technologies Ltd. MSN3700/VMOD0005, BIOS 5.11 01/06/2019

Workqueue: mlxsw_core mlxsw_sp_acl_tcam_vregion_rehash_work

Call Trace:

<TASK>

dump_stack_lvl+0xc6/0x120

print_report+0xce/0x670

kasan_report+0xd7/0x110

mlxsw_sp_acl_ctcam_region_entry_remove+0x21d/0x230

mlxsw_sp_acl_ctcam_entry_del+0x2e/0x70

mlxsw_sp_acl_atcam_entry_del+0x81/0x210

mlxsw_sp_acl_tcam_vchunk_migrate_all+0x3cd/0xb50

mlxsw_sp_acl_tcam_vregion_rehash_work+0x157/0x1300

process_one_work+0x8eb/0x19b0

worker_thread+0x6c9/0xf70

kthread+0x2c9/0x3b0

ret_from_fork+0x4d/0x80

ret_from_fork_asm+0x1a/0x30

</TASK>

Allocated by task 174:

kasan_save_stack+0x33/0x60

kasan_save_track+0x14/0x30

__kasan_kmalloc+0x8f/0xa0

__kmalloc+0x19c/0x360

mlxsw_sp_acl_tcam_region_create+0xdf/0x9c0

mlxsw_sp_acl_tcam_vregion_rehash_work+0x954/0x1300

process_one_work+0x8eb/0x19b0

worker_thread+0x6c9/0xf70

kthread+0x2c9/0x3b0

ret_from_fork+0x4d/0x80

ret_from_fork_asm+0x1a/0x30

Freed by task 7:

kasan_save_stack+0x33/0x60

kasan_save_track+0x14/0x30

kasan_save_free_info+0x3b/0x60

poison_slab_object+0x102/0x170

__kasan_slab_free+0x14/0x30

kfree+0xc1/0x290

mlxsw_sp_acl_tcam_region_destroy+0x272/0x310

mlxsw_sp_acl_tcam_vregion_rehash_work+0x731/0x1300

process_one_work+0x8eb/0x19b0

worker_thread+0x6c9/0xf70

kthread+0x2c9/0x3b0

ret_from_fork+0x4d/0x80

ret_from_fork_asm+0x1a/0x30

Affected software

AZL-42100 is recorded against 1 package.

  • hyperv-daemons (fixed in 6.6.35.1-1)

Timeline and source

Published on 17 May 2024 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-05-17
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
hyperv-daemons 6.6.35.1-1

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-42100?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-42100 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesAzure LinuxAzure Linux Undated