Junglewise Threat Intelligence

CVE-2024-26961: Linux kernel use-after-free in mac802154 security key deletion

CVE-2024-26961 · Severity: high · CVSS 7.8 · Published 2024-05-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component for low-power wireless networks (IEEE 802.15.4) could allow a local attacker to crash the system or potentially gain unauthorized access to data. The issue occurs when security keys are deleted while they are still being accessed by other parts of the system. This can lead to a 'use-after-free' condition, which impacts the overall stability and security of devices using this specific wireless protocol.

Technical details

A use-after-free vulnerability exists in the mac802154_llsec_key_del() function within the Linux kernel's IEEE 802.15.4 implementation. The root cause is that the function frees key resources directly without adhering to Read-Copy-Update (RCU) grace period rules, leading to a race condition when llsec_lookup_key() traverses the key list simultaneously. Additionally, the ieee802154_llsec_key_entry structures were not being properly freed, causing a memory leak. A local attacker can exploit this to trigger a kernel panic (DoS) or potentially achieve privilege escalation. The fix introduces a proper RCU callback (mac802154_llsec_key_del_rcu) to ensure resources are only released after the grace period.

Affected products

  • Linux Linux kernel 3.16 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2

Timeline

  • 2024-02-28: patched: Initial patch submitted by Fedor Pchelkin
  • 2024-05-01: advisory: CVE-2024-26961 published

References

Related threats