CVE-2024-11263
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-11263 is a critical security vulnerability discovered in the Zephyr Real-Time Operating System (RTOS) affecting versions up to and including 3.7. The vulnerability was disclosed on November 15, 2024, and relates to the Global Pointer (GP) relative addressing feature when enabled through CONFIGRISCVGP=y configuration (Zephyr Advisory).

Technical details

The vulnerability occurs when Global Pointer (GP) relative addressing is enabled (CONFIGRISCVGP=y). In this configuration, the gp register points at 0x800 bytes past the start of the .sdata section, which is used by the linker to relax accesses to global symbols. The critical security flaw lies in the lack of protection for the gp register against writes from userspace, allowing potential manipulation by unauthorized users. The vulnerability has received a CVSS v3.1 base score of 9.3 CRITICAL with vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (NVD).

Impact

The vulnerability can allow a rogue thread to corrupt the gp register, potentially causing the entire system to hard fault. In more severe scenarios, it could trick the system into accessing random global symbols, leading to system compromise. The impact is particularly severe as it affects system integrity, confidentiality, and availability with high severity ratings (Zephyr Advisory).

Mitigation and workarounds

Two patches have been proposed to address this vulnerability: #81155 for the main branch and #81370 for v3.7. The expected behavior is that the gp register should remain constant. Users are advised to apply these patches to protect their systems (Zephyr Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management