Executive brief
A vulnerability in the Linux kernel's networking component could allow a local attacker to cause a system crash. The issue occurs when the system's 'garbage collector'—which cleans up unused resources—conflicts with new network connections. This can lead to memory corruption, resulting in a denial-of-service (system instability or crash).
Technical details
A race condition exists in the AF_UNIX implementation of the Linux kernel between the garbage collector (GC) and the connect() system call. The GC fails to account for 'embryo' sockets (partially initialized connections) being enqueued during the collection process. If an embryo carries SCM_RIGHTS (file descriptor passing), consecutive passes of the GC's scan_children() function may observe inconsistent states. This leads to an incorrectly elevated 'inflight' count and a subsequent dangling pointer within the gc_inflight_list. An attacker with local access can exploit this race to trigger a kernel panic or memory corruption. The fix involves ensuring the GC waits for ongoing connect() operations by locking the state of candidate listening sockets.
Affected products
- Linux Linux Kernel 2.6.23 to 4.19.314, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.156, 5.16 to 6.1.87, 6.2 to 6.6.28, 6.7 to 6.8.7
Timeline
- 2024-04-09: patched: Initial patch submitted by Michal Luczaj
- 2024-04-25: advisory: CVE-2024-26923 published
References
- https://git.kernel.org/stable/c/2e2a03787f4f0abc0072350654ab0ef3324d9db3
- https://git.kernel.org/stable/c/343c5372d5e17b306db5f8f3c895539b06e3177f
- https://git.kernel.org/stable/c/47d8ac011fe1c9251070e1bd64cb10b48193ec51
- https://git.kernel.org/stable/c/507cc232ffe53a352847893f8177d276c3b532a9
- https://git.kernel.org/stable/c/a36ae0ec2353015f0f6762e59f4c2dbc0c906423
- https://git.kernel.org/stable/c/b75722be422c276b699200de90527d01c602ea7c
- https://git.kernel.org/stable/c/dbdf7bec5c920200077d693193f989cb1513f009