Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-41041— udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().

CVSS 7.8 · High EPSS 0.29% · P21

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinux6acc9b432e6714d72d7d77ec7c27f6f8358d0c71< 7a67c4e47626e6daccda62888f8b096abb5d3940affected
6acc9b432e6714d72d7d77ec7c27f6f8358d0c71< 9f965684c57c3117cfd2f754dd3270383c529fbaaffected
6acc9b432e6714d72d7d77ec7c27f6f8358d0c71< ddf516e50bf8a7bc9b3bd8a9831f9c7a8131a32aaffected
6acc9b432e6714d72d7d77ec7c27f6f8358d0c71< a6db0d3ea6536e7120871e5448b3032570152ec6affected
6acc9b432e6714d72d7d77ec7c27f6f8358d0c71< c5fd77ca13d657c6e99bf04f0917445e6a80231eaffected
6acc9b432e6714d72d7d77ec7c27f6f8358d0c71< 20ceae10623c3b29fdf7609690849475bcdebdb0affected
6acc9b432e6714d72d7d77ec7c27f6f8358d0c71< 5c0b485a8c6116516f33925b9ce5b6104a6eadfdaffected
4.20affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-41041

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port(). syzkaller triggered the warning [0] in udp_v4_early_demux(). In udp_v[46]_early_demux() and sk_lookup(), we do not touch the refcount of the looked-up sk and use sock_pfree() as skb->destructor, so we check SOCK_RCU_FREE to ensure that the sk is safe to access during the RCU grace period. Currently, SOCK_RCU_FREE is flagged for a bound socket after being put into the hash table. Moreover, the SOCK_RCU_FREE check is done too early in udp_v[46]_early_demux() and sk_lookup(), so there could be a small race window: CPU1 CPU2 ---- ---- udp_v4_early_demux() udp_lib_get_port() | |- hlist_add_head_rcu() |- sk = __udp4_lib_demux_lookup() | |- DEBUG_NET_WARN_ON_ONCE(sk_is_refcounted(sk)); `- sock_set_flag(sk, SOCK_RCU_FREE) We had the same bug in TCP and fixed it in commit 871019b22d1b ("net: set SOCK_RCU_FREE before inserting socket into hashtable"). Let's apply the same fix for UDP. [0]: WARNING: CPU: 0 PID: 11198 at net/ipv4/udp.c:2599 udp_v4_early_demux+0x481/0xb70 net/ipv4/udp.c:2599 Modules linked in: CPU: 0 PID: 11198 Comm: syz-executor.1 Not tainted 6.9.0-g93bda33046e7 #13 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 RIP: 0010:udp_v4_early_demux+0x481/0xb70 net/ipv4/udp.c:2599 Code: c5 7a 15 fe bb 01 00 00 00 44 89 e9 31 ff d3 e3 81 e3 bf ef ff ff 89 de e8 2c 74 15 fe 85 db 0f 85 02 06 00 00 e8 9f 7a 15 fe <0f> 0b e8 98 7a 15 fe 49 8d 7e 60 e8 4f 39 2f fe 49 c7 46 60 20 52 RSP: 0018:ffffc9000ce3fa58 EFLAGS: 00010293 RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffff8318c92c RDX: ffff888036ccde00 RSI: ffffffff8318c2f1 RDI: 0000000000000001 RBP: ffff88805a2dd6e0 R08: 0000000000000001 R09: 0000000000000000 R10: 0000000000000000 R11: 0001ffffffffffff R12: ffff88805a2dd680 R13: 0000000000000007 R14: ffff88800923f900 R15: ffff88805456004e FS: 00007fc449127640(0000) GS:ffff88807dc00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fc449126e38 CR3: 000000003de4b002 CR4: 0000000000770ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000600 PKRU: 55555554 Call Trace: <TASK> ip_rcv_finish_core.constprop.0+0xbdd/0xd20 net/ipv4/ip_input.c:349 ip_rcv_finish+0xda/0x150 net/ipv4/ip_input.c:447 NF_HOOK include/linux/netfilter.h:314 [inline] NF_HOOK include/linux/netfilter.h:308 [inline] ip_rcv+0x16c/0x180 net/ipv4/ip_input.c:569 __netif_receive_skb_one_core+0xb3/0xe0 net/core/dev.c:5624 __netif_receive_skb+0x21/0xd0 net/core/dev.c:5738 netif_receive_skb_internal net/core/dev.c:5824 [inline] netif_receive_skb+0x271/0x300 net/core/dev.c:5884 tun_rx_batched drivers/net/tun.c:1549 [inline] tun_get_user+0x24db/0x2c50 drivers/net/tun.c:2002 tun_chr_write_iter+0x107/0x1a0 drivers/net/tun.c:2048 new_sync_write fs/read_write.c:497 [inline] vfs_write+0x76f/0x8d0 fs/read_write.c:590 ksys_write+0xbf/0x190 fs/read_write.c:643 __do_sys_write fs/read_write.c:655 [inline] __se_sys_write fs/read_write.c:652 [inline] __x64_sys_write+0x41/0x50 fs/read_write.c:652 x64_sys_call+0xe66/0x1990 arch/x86/include/generated/asm/syscalls_64.h:2 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0x4b/0x110 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7fc44a68bc1f Code: 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 e9 cf f5 ff 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 31 44 89 c7 48 89 44 24 08 e8 3c d0 f5 ff 48 RSP: 002b:00007fc449126c90 EFLAGS: 00000293 ORIG_RAX: 0000000000000001 RAX: ffffffffffffffda RBX: 00000000004bc050 RCX: 00007fc44a68bc1f R ---truncated---
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在udp_lib_get_port函数中,SOCK_RCU_FREE标志的设置太早,可能导致在RCU宽限期内访问不安全的sk。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 6acc9b432e6714d72d7d77ec7c27f6f8358d0c71 ~ 7a67c4e47626e6daccda62888f8b096abb5d3940 -
LinuxLinux 4.20 -

II. Public POCs for CVE-2024-41041

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-41041

登录查看更多情报信息。

Other References for CVE-2024-41041 (6)

Same Patch Batch · Linux · 2024-07-29 · 121 CVEs total

CVE-2024-410409.8 CRITICALnet/sched: Fix UAF when resolving a clash
CVE-2024-410819.8 CRITICALila: block BH in ila_output()
CVE-2024-410739.8 CRITICALnvme: avoid double free special payload
CVE-2024-410918.8 HIGHtun: add missing verification for short frame
CVE-2024-410908.8 HIGHtap: add missing verification for short frame
CVE-2024-410468.8 HIGHnet: ethernet: lantiq_etop: fix double free in detach
CVE-2024-420838.8 HIGHionic: fix kernel panic due to multi-buffer handling
CVE-2024-410628.8 HIGHbluetooth/l2cap: sync sock recv cb and release
CVE-2024-410457.8 HIGHbpf: Defer work in bpf_timer_cancel_and_free
CVE-2024-410517.8 HIGHcachefiles: wait for ondemand_object_worker to finish when dropping object
CVE-2024-410497.8 HIGHfilelock: fix potential use-after-free in posix_lock_inode
CVE-2024-410577.8 HIGHcachefiles: fix slab-use-after-free in cachefiles_withdraw_cookie()
CVE-2024-410607.8 HIGHdrm/radeon: check bo_va->bo is non-NULL before using it
CVE-2024-410597.8 HIGHhfsplus: fix uninit-value in copy_name
CVE-2024-420757.8 HIGHbpf: Fix remap of arena.
CVE-2024-410647.8 HIGHpowerpc/eeh: avoid possible crash when edev->pdev changes
CVE-2024-420727.8 HIGHbpf: Fix may_goto with negative offset.
CVE-2024-420647.8 HIGHdrm/amd/display: Skip pipe if the pipe idx not set properly
CVE-2024-410867.8 HIGHbcachefs: Fix sb_field_downgrade validation
CVE-2024-410877.8 HIGHata: libata-core: Fix double free on error

Showing top 20 of 121 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-41041

No comments yet


Leave a comment