Executive brief
A vulnerability was identified in the Linux kernel's High-availability Seamless Redundancy (HSR) networking component. This component is used to provide high-reliability networking for industrial automation and critical infrastructure. An attacker could exploit this flaw to cause a system crash or instability, potentially leading to a denial of service for the affected device.
Technical details
An uninitialized value access vulnerability exists in the hsr_get_node() function within net/hsr/hsr_framereg.c of the Linux kernel. The issue occurs when an Ethernet header specifies a packet type of ETH_P_PRP or ETH_P_HSR but is not actually followed by the expected HSR tag. In this scenario, hsr_get_skb_sequence_nr() attempts to read a sequence number from uninitialized memory. This can be triggered by a local attacker sending specially crafted packets, resulting in a kernel panic or denial of service. The fix introduces a check to ensure the socket buffer (skb) contains a valid hsr_ethhdr before processing.
Affected products
- Linux Linux Kernel 3.17 to 4.19.311, 4.20 to 5.4.273, 5.5 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11
Timeline
- 2024-03-13: patched: Initial patch submitted by Shigeru Yoshida
- 2024-04-17: disclosed: CVE published
References
- https://git.kernel.org/stable/c/09e5cdbe2cc88c3c758927644a3eb02fac317209
- https://git.kernel.org/stable/c/1ed222ca7396938eb1ab2d034f1ba0d8b00a7122
- https://git.kernel.org/stable/c/39cc316fb3bc5e7c9dc5eed314fe510d119c6862
- https://git.kernel.org/stable/c/7fb2d4d6bb1c85f7a23aace0ed6c86a95dea792a
- https://git.kernel.org/stable/c/889ed056eae7fda85b769a9ab33c093379c45428
- https://git.kernel.org/stable/c/97d2148ea435dff4b4e71817c9032eb321bcd37e
- https://git.kernel.org/stable/c/a809bbfd0e503351d3051317288a70a4569a4949