CVE-2024-35875
Last modified
CVE-2024-35875 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: x86/coco: Require seeding RNG with RDRAND on CoCo systems There are few uses of CoCo that don't rely on working cryptography and hence a working RNG. Unfortunately, the CoCo threat model means that the VM host cannot be trusted and may actively work against guests to extract secrets or manipulate computation. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: x86/coco: Require seeding RNG with RDRAND on CoCo systems There are few uses of CoCo that don't rely on working cryptography and hence a working RNG. Unfortunately, the CoCo threat model means that the VM host cannot be trusted and may actively work against guests to extract secrets or manipulate computation. Since a malicious host can modify or observe nearly all inputs to guests, the only remaining source of entropy for CoCo guests is RDRAND. If RDRAND is broken -- due to CPU hardware fault -- the RNG as a whole is meant to gracefully continue on gathering entropy from other sources, but since there aren't other sources on CoCo, this is catastrophic. This is mostly a concern at boot time when initially seeding the RNG, as after that the consequences of a broken RDRAND are much more theoretical. So, try at boot to seed the RNG using 256 bits of RDRAND output. If this fails, panic(). This will also trigger if the system is booted without RDRAND, as RDRAND is essential for a safe CoCo boot. Add this deliberately to be "just a CoCo x86 driver feature" and not part of the RNG itself. Many device drivers and platforms have some desire to contribute something to the RNG, and add_device_randomness() is specifically meant for this purpose. Any driver can call it with seed data of any quality, or even garbage quality, and it can only possibly make the quality of the RNG better or have no effect, but can never make it worse. Rather than trying to build something into the core of the RNG, consider the particular CoCo issue just a CoCo issue, and therefore separate it all out into driver (well, arch/platform) code. [ bp: Massage commit message. ]
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | < 6.1.85 | — |
| Linux | Linux Kernel | >= 6.2, < 6.6.26 | — |
| Linux | Linux Kernel | >= 6.7, < 6.8.5 | — |
| Linux | Linux Kernel | 6.9 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-35875?
How severe is CVE-2024-35875?
How do I fix CVE-2024-35875?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-3587The Premium Portfolio Features for Phlox theme plugin for Wo…5.4
- CVE-2024-35870In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2024-35871In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2024-35872In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-35873In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-35874In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-35876Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-35877In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-35878In the Linux kernel, the following vulnerability has been re…5.3
- CVE-2024-35879In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-3588The Getwid – Gutenberg Blocks plugin for WordPress is vulner…5.4
- CVE-2024-35880In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2024-35875?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
