Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-26865— rds: tcp: Fix use-after-free of net in reqsk_timer_handler().

CVSS 7.8 · High EPSS 0.23% · P14

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinux467fa15356acfb7b2efa38839c3e76caa4e6e0ea< 9905a157048f441f1412e7bd13372f4a971d75c6affected
467fa15356acfb7b2efa38839c3e76caa4e6e0ea< f901ee07853ce97e9f1104c7c898fbbe447f0279affected
467fa15356acfb7b2efa38839c3e76caa4e6e0ea< 9ceac040506a05a30b104b2aa2e9146810704500affected
467fa15356acfb7b2efa38839c3e76caa4e6e0ea< 1e9fd5cf8d7f487332560f7bb312fc7d416817f3affected
467fa15356acfb7b2efa38839c3e76caa4e6e0ea< 2a750d6a5b365265dbda33330a6188547ddb5c24affected
4.3affected
< 4.3unaffected
6.1.83≤ 6.1.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-26865

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
rds: tcp: Fix use-after-free of net in reqsk_timer_handler().
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: rds: tcp: Fix use-after-free of net in reqsk_timer_handler(). syzkaller reported a warning of netns tracker [0] followed by KASAN splat [1] and another ref tracker warning [1]. syzkaller could not find a repro, but in the log, the only suspicious sequence was as follows: 18:26:22 executing program 1: r0 = socket$inet6_mptcp(0xa, 0x1, 0x106) ... connect$inet6(r0, &(0x7f0000000080)={0xa, 0x4001, 0x0, @loopback}, 0x1c) (async) The notable thing here is 0x4001 in connect(), which is RDS_TCP_PORT. So, the scenario would be: 1. unshare(CLONE_NEWNET) creates a per netns tcp listener in rds_tcp_listen_init(). 2. syz-executor connect()s to it and creates a reqsk. 3. syz-executor exit()s immediately. 4. netns is dismantled. [0] 5. reqsk timer is fired, and UAF happens while freeing reqsk. [1] 6. listener is freed after RCU grace period. [2] Basically, reqsk assumes that the listener guarantees netns safety until all reqsk timers are expired by holding the listener's refcount. However, this was not the case for kernel sockets. Commit 740ea3c4a0b2 ("tcp: Clean up kernel listener's reqsk in inet_twsk_purge()") fixed this issue only for per-netns ehash. Let's apply the same fix for the global ehash. [0]: ref_tracker: net notrefcnt@0000000065449cc3 has 1/1 users at sk_alloc (./include/net/net_namespace.h:337 net/core/sock.c:2146) inet6_create (net/ipv6/af_inet6.c:192 net/ipv6/af_inet6.c:119) __sock_create (net/socket.c:1572) rds_tcp_listen_init (net/rds/tcp_listen.c:279) rds_tcp_init_net (net/rds/tcp.c:577) ops_init (net/core/net_namespace.c:137) setup_net (net/core/net_namespace.c:340) copy_net_ns (net/core/net_namespace.c:497) create_new_namespaces (kernel/nsproxy.c:110) unshare_nsproxy_namespaces (kernel/nsproxy.c:228 (discriminator 4)) ksys_unshare (kernel/fork.c:3429) __x64_sys_unshare (kernel/fork.c:3496) do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129) ... WARNING: CPU: 0 PID: 27 at lib/ref_tracker.c:179 ref_tracker_dir_exit (lib/ref_tracker.c:179) [1]: BUG: KASAN: slab-use-after-free in inet_csk_reqsk_queue_drop (./include/net/inet_hashtables.h:180 net/ipv4/inet_connection_sock.c:952 net/ipv4/inet_connection_sock.c:966) Read of size 8 at addr ffff88801b370400 by task swapper/0/0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 Call Trace: <IRQ> dump_stack_lvl (lib/dump_stack.c:107 (discriminator 1)) print_report (mm/kasan/report.c:378 mm/kasan/report.c:488) kasan_report (mm/kasan/report.c:603) inet_csk_reqsk_queue_drop (./include/net/inet_hashtables.h:180 net/ipv4/inet_connection_sock.c:952 net/ipv4/inet_connection_sock.c:966) reqsk_timer_handler (net/ipv4/inet_connection_sock.c:979 net/ipv4/inet_connection_sock.c:1092) call_timer_fn (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/timer.h:127 kernel/time/timer.c:1701) __run_timers.part.0 (kernel/time/timer.c:1752 kernel/time/timer.c:2038) run_timer_softirq (kernel/time/timer.c:2053) __do_softirq (./arch/x86/include/asm/jump_label.h:27 ./include/linux/jump_label.h:207 ./include/trace/events/irq.h:142 kernel/softirq.c:554) irq_exit_rcu (kernel/softirq.c:427 kernel/softirq.c:632 kernel/softirq.c:644) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1076 (discriminator 14)) </IRQ> Allocated by task 258 on cpu 0 at 83.612050s: kasan_save_stack (mm/kasan/common.c:48) kasan_save_track (mm/kasan/common.c:68) __kasan_slab_alloc (mm/kasan/common.c:343) kmem_cache_alloc (mm/slub.c:3813 mm/slub.c:3860 mm/slub.c:3867) copy_net_ns (./include/linux/slab.h:701 net/core/net_namespace.c:421 net/core/net_namespace.c:480) create_new_namespaces (kernel/nsproxy.c:110) unshare_nsproxy_name ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于内存释放后重用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 467fa15356acfb7b2efa38839c3e76caa4e6e0ea ~ 9905a157048f441f1412e7bd13372f4a971d75c6 -
LinuxLinux 4.3 -

II. Public POCs for CVE-2024-26865

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-26865

登录查看更多情报信息。

Other References for CVE-2024-26865 (5)

Same Patch Batch · Linux · 2024-04-17 · 100 CVEs total

CVE-2024-268779.8 CRITICALcrypto: xilinx - call finalize with bh disabled
CVE-2024-268539.8 CRITICALigc: avoid returning frame twice in XDP_REDIRECT
CVE-2024-268289.4 CRITICALcifs: fix underflow in parse_server_interfaces()
CVE-2024-268568.8 HIGHnet: sparx5: Fix use after free inside sparx5_del_mact_entry
CVE-2024-268228.7 HIGHsmb: client: set correct id, uid and cruid for multiuser automounts
CVE-2024-268308.4 HIGHi40e: Do not allow untrusted VF to remove administratively set MAC
CVE-2024-268247.8 HIGHcrypto: algif_hash - Remove bogus SGL free on zero-length error path
CVE-2024-268987.8 HIGHaoe: fix the potential use-after-free problem in aoecmd_cfg_pkts
CVE-2024-268387.8 HIGHRDMA/irdma: Fix KASAN issue with tasklet
CVE-2024-268527.8 HIGHnet/ipv6: avoid possible UAF in ip6_route_mpath_notify()
CVE-2024-268957.8 HIGHwifi: wilc1000: prevent use-after-free on vif when cleaning up all interfaces
CVE-2024-268907.8 HIGHBluetooth: btrtl: fix out of bounds memory access
CVE-2024-268647.8 HIGHtcp: Fix refcnt handling in __inet_hash_connect().
CVE-2024-268697.8 HIGHf2fs: fix to truncate meta inode pages forcely
CVE-2024-268707.8 HIGHNFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102
CVE-2024-268727.8 HIGHRDMA/srpt: Do not register event handler until srpt device is fully setup
CVE-2024-268857.8 HIGHbpf: Fix DEVMAP_HASH overflow check on 32-bit arches
CVE-2024-268847.8 HIGHbpf: Fix hashtab overflow check on 32-bit arches
CVE-2024-268837.8 HIGHbpf: Fix stackmap overflow check on 32-bit arches
CVE-2024-268807.8 HIGHdm: call the resume method on internal suspend

Showing top 20 of 100 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26865

No comments yet


Leave a comment