Executive brief
A vulnerability exists in the WireGuard component of the Linux kernel, which is used for secure virtual private network (VPN) connections. A local attacker could exploit this flaw to cause a system crash (denial of service) by triggering a memory error during network configuration tasks. This could disrupt secure communications and impact the availability of the affected system.
Technical details
A NULL pointer dereference vulnerability exists in the WireGuard implementation within the Linux kernel, specifically in the netlink configuration interface (drivers/net/wireguard/netlink.c). The issue arises in the get_peer function where the code attempted to access device properties via a peer pointer (peer->device) that could be NULL or point to a freed object. An attacker with local privileges could trigger this condition during netlink dump operations, leading to a kernel oops and system denial of service. The fix changes the implementation to access the device through the dump context (ctx->wg) instead of the peer object, providing better memory safety and defense-in-depth against use-after-free scenarios. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.6 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3
Timeline
- 2024-03-14: other: Initial patch authored
- 2024-05-01: disclosed: CVE published
References
- https://git.kernel.org/stable/c/09c3fa70f65175861ca948cb2f0f791e666c90e5
- https://git.kernel.org/stable/c/493aa6bdcffd90a4f82aa614fe4f4db0641b4068
- https://git.kernel.org/stable/c/4be453271a882c8ebc28df3dbf9e4d95e6ac42f5
- https://git.kernel.org/stable/c/71cbd32e3db82ea4a74e3ef9aeeaa6971969c86f
- https://git.kernel.org/stable/c/93bcc1752c69bb309f4d8cfaf960ef1faeb34996
- https://git.kernel.org/stable/c/c991567e6c638079304cc15dff28748e4a3c4a37
- https://git.kernel.org/stable/c/d44bd323d8bb8031eef4bdc44547925998a11e47