Executive brief
A vulnerability was identified in the Linux kernel's IPv6 networking component that could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system handles specific types of network routing updates, leading to a memory error known as a use-after-free. This could impact the stability and security of servers and workstations running affected versions of Linux.
Technical details
A use-after-free (UAF) vulnerability exists in the net/ipv6 component of the Linux kernel, specifically within the ip6_route_mpath_notify() function. The root cause is a premature call to fib6_info_release() during multipath route notification, which allows the system to access memory that has already been freed. An attacker with local access could trigger this condition by sending specific Netlink messages to add IPv6 routes. This vulnerability was discovered by syzbot and follows an incomplete previous fix (commit f7225172f25a). The resolution involves deferring the release of routing information until the cleanup phase after notifications are complete. Patches have been released for various stable kernel branches.
Affected products
- Linux Linux Kernel 6.8.0-rc4 and earlier
Timeline
- 2024-03-03: patched: Initial fix authored by Eric Dumazet
- 2024-04-17: advisory: CVE-2024-26852 published
References
- https://git.kernel.org/stable/c/31ea5bcc7d4cd1423de6be327a2c034725704136
- https://git.kernel.org/stable/c/394334fe2ae3b9f1e2332b873857e84cb28aac18
- https://git.kernel.org/stable/c/61b34f73cdbdb8eaf9ea12e9e2eb3b29716c4dda
- https://git.kernel.org/stable/c/664f9c647260cc9d68b4e31d9899530d89dd045e
- https://git.kernel.org/stable/c/685f7d531264599b3f167f1e94bbd22f120e5fab
- https://git.kernel.org/stable/c/79ce2e54cc0ae366f45516c00bf1b19aa43e9abe
- https://git.kernel.org/stable/c/cae3303257950d03ffec2df4a45e836f10d26c24