Junglewise Threat Intelligence

CVE-2024-26950: Linux Kernel NULL pointer dereference in WireGuard netlink

CVE-2024-26950 · Severity: medium · CVSS 5.5 · Published 2024-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the WireGuard component of the Linux kernel, which is used for secure virtual private network (VPN) connections. A local attacker could exploit this flaw to cause a system crash (denial of service) by triggering a memory error during network configuration tasks. This could disrupt secure communications and impact the availability of the affected system.

Technical details

A NULL pointer dereference vulnerability exists in the WireGuard implementation within the Linux kernel, specifically in the netlink configuration interface (drivers/net/wireguard/netlink.c). The issue arises in the get_peer function where the code attempted to access device properties via a peer pointer (peer->device) that could be NULL or point to a freed object. An attacker with local privileges could trigger this condition during netlink dump operations, leading to a kernel oops and system denial of service. The fix changes the implementation to access the device through the dump context (ctx->wg) instead of the peer object, providing better memory safety and defense-in-depth against use-after-free scenarios. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 5.6 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3

Timeline

  • 2024-03-14: other: Initial patch authored
  • 2024-05-01: disclosed: CVE published

References

Related threats