Junglewise Threat Intelligence

CVE-2024-26958: Linux Kernel NFS use-after-free in direct writes

CVE-2024-26958 · Severity: high · CVSS 7.8 · Published 2024-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Network File System (NFS) component that could lead to a system crash or unauthorized memory access. The issue occurs during specific high-speed data writing operations where the system incorrectly handles internal tracking of data requests. This could allow a local user to destabilize the system or potentially gain elevated privileges, impacting the reliability and security of servers using NFS for storage.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel NFS client's direct write path due to a double-completion of 'nfs_direct_request'. When asynchronous commit requests are submitted, a race condition allows one request to complete before the next is submitted, leading to multiple calls to 'nfs_direct_write_complete' and a subsequent refcount underflow. This occurs because the 'nfs_direct_commit_schedule' function lacked proper 'nfs_commit_begin' and 'nfs_commit_end' wrapping to synchronize completion handling. An attacker with local access could exploit this to cause a kernel panic or execute arbitrary code. The issue has been patched in various stable branches including 5.10.215, 5.15.154, 6.1.84, 6.6.24, 6.7.12, and 6.8.3.

Affected products

  • Linux Linux Kernel up to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.84, 6.2 to 6.6.24, 6.7 to 6.7.12, 6.8 to 6.8.3

Timeline

  • 2024-03-01: patched: Initial patch authored by Josef Bacik
  • 2024-05-01: advisory: CVE-2024-26958 published in NVD

References

Related threats