Junglewise Threat Intelligence

CVE-2024-26898: Linux Kernel use-after-free in AoE driver aoecmd_cfg_pkts

CVE-2024-26898 · Severity: high · CVSS 7.8 · Published 2024-04-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's ATA over Ethernet (AoE) driver, which is used to access storage devices over a network. A flaw in how the system manages memory for network interfaces can allow a local attacker to crash the system or potentially execute unauthorized code. This could lead to a complete system outage or a breach of sensitive data.

Technical details

A use-after-free vulnerability exists in the Linux kernel's ATA over Ethernet (AoE) driver. The root cause is located in the aoecmd_cfg_pkts() function, which prematurely decrements the reference count (dev_put) of a 'net_device' structure while it is still queued for transmission in a separate kernel thread (tx()). An attacker with local access can trigger a race condition between the freeing of the structure and its subsequent access in the global 'skbtxq' queue. This can result in a kernel panic (Denial of Service) or potentially arbitrary code execution. The issue has been patched by ensuring the reference count is maintained until the transmission process is complete.

Affected products

  • Linux Linux Kernel 2.6.22 to 4.19.310, 4.20 to 5.4.272, 5.5 to 5.10.213, 5.11 to 5.15.152, 5.16 to 6.1.82, 6.2 to 6.6.22, 6.7 to 6.8.1

Timeline

  • 2024-03-05: patched: Initial patch submitted by Chun-Yi Lee
  • 2024-04-17: disclosed: CVE-2024-26898 published

References

Related threats