Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow an attacker to cause a system crash. The issue exists in the H.323 protocol handler, which is used for managing multimedia communications like voice and video calls. By sending specially crafted network data, an attacker could trigger an internal error that halts the system, leading to a denial of service.
Technical details
An undefined behavior vulnerability exists in the nf_conntrack_h323 module of the Linux kernel due to insufficient validation of bitmap lengths during ASN.1 decoding of RAS (Registration, Admission, and Status) messages. Specifically, in the decode_seq function within nf_conntrack_h323_asn1.c, an extension bitmap length can exceed 32 bits when processing abnormal skb data. This results in an out-of-bounds bitwise shift operation, which UBSAN identifies as undefined behavior and can lead to a kernel exception (BRK#5515). The fix introduces bounds checking to ensure the bitmap length (f->sz and bmp2_len) does not exceed 32, returning an H323_ERROR_RANGE if it does. This vulnerability is reachable via network traffic if H.323 connection tracking is enabled.
Affected products
- Linux Linux Kernel 2.6.17 to 4.19.310, 4.20 to 5.4.272, 5.5 to 5.10.213, 5.11 to 5.15.152, 5.16 to 6.1.82, 6.2 to 6.6.22, 6.7 to 6.7.10, 6.8.rc1 to 6.8.rc6
Timeline
- 2024-03-15: patched: Fix committed to stable kernel trees.
- 2024-04-17: disclosed: CVE published.
References
- https://git.kernel.org/stable/c/014a807f1cc9c9d5173c1cd935835553b00d211c
- https://git.kernel.org/stable/c/39001e3c42000e7c2038717af0d33c32319ad591
- https://git.kernel.org/stable/c/4bafcc43baf7bcf93566394dbd15726b5b456b7a
- https://git.kernel.org/stable/c/767146637efc528b5e3d31297df115e85a2fd362
- https://git.kernel.org/stable/c/80ee5054435a11c87c9a4f30f1ff750080c96416
- https://git.kernel.org/stable/c/98db42191329c679f4ca52bec0b319689e1ad8cb
- https://git.kernel.org/stable/c/b3c0f553820516ad4b62a9390ecd28d6f73a7b13