Executive brief
A vulnerability exists in the Linux kernel's ATA over Ethernet (AoE) driver, which is used to access storage devices over a network. A flaw in how the system manages memory for network interfaces can allow a local attacker to crash the system or potentially execute unauthorized code. This could lead to a complete system outage or a breach of sensitive data.
Technical details
A use-after-free vulnerability exists in the Linux kernel's ATA over Ethernet (AoE) driver. The root cause is located in the aoecmd_cfg_pkts() function, which prematurely decrements the reference count (dev_put) of a 'net_device' structure while it is still queued for transmission in a separate kernel thread (tx()). An attacker with local access can trigger a race condition between the freeing of the structure and its subsequent access in the global 'skbtxq' queue. This can result in a kernel panic (Denial of Service) or potentially arbitrary code execution. The issue has been patched by ensuring the reference count is maintained until the transmission process is complete.
Affected products
- Linux Linux Kernel 2.6.22 to 4.19.310, 4.20 to 5.4.272, 5.5 to 5.10.213, 5.11 to 5.15.152, 5.16 to 6.1.82, 6.2 to 6.6.22, 6.7 to 6.8.1
Timeline
- 2024-03-05: patched: Initial patch submitted by Chun-Yi Lee
- 2024-04-17: disclosed: CVE-2024-26898 published
References
- https://git.kernel.org/stable/c/079cba4f4e307c69878226fdf5228c20aa1c969c
- https://git.kernel.org/stable/c/1a54aa506b3b2f31496731039e49778f54eee881
- https://git.kernel.org/stable/c/74ca3ef68d2f449bc848c0a814cefc487bf755fa
- https://git.kernel.org/stable/c/7dd09fa80b0765ce68bfae92f4e2f395ccf0fba4
- https://git.kernel.org/stable/c/a16fbb80064634b254520a46395e36b87ca4731e
- https://git.kernel.org/stable/c/ad80c34944d7175fa1f5c7a55066020002921a99
- https://git.kernel.org/stable/c/eb48680b0255a9e8a9bdc93d6a55b11c31262e62