Executive brief
A vulnerability in the Linux kernel's initialization process could allow for a memory overflow during system startup. The kernel incorrectly calculates the amount of memory needed to store system startup commands, which could lead to memory corruption. If exploited, this could allow a local user to compromise the integrity of the operating system or cause a system crash.
Technical details
An out-of-bounds write vulnerability exists in the 'setup_command_line' function within 'init/main.c' of the Linux kernel. The root cause is a calculation error where the kernel allocates memory based on the length of 'boot_command_line' but subsequently copies 'command_line' into that buffer. If 'command_line' is longer than 'boot_command_line', a heap-based buffer overflow occurs. This is a regression introduced by a previous commit that mis-consolidated string length checks. An attacker with local access could potentially leverage this overflow to corrupt kernel memory during the boot process. Patches have been released for multiple stable kernel branches including 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.8.y.
Affected products
- Linux Linux Kernel 5.1 to 5.10.216, 5.11 to 5.15.157, 5.16 to 6.1.88, 6.2 to 6.6.29, 6.7 to 6.8.8
Timeline
- 2024-04-12: disclosed: Initial patch submitted by Yuntao Wang
- 2024-05-01: advisory: CVE-2024-26988 published
References
- https://git.kernel.org/stable/c/0dc727a4e05400205358a22c3d01ccad2c8e1fe4
- https://git.kernel.org/stable/c/2ef607ea103616aec0289f1b65d103d499fa903a
- https://git.kernel.org/stable/c/46dad3c1e57897ab9228332f03e1c14798d2d3b9
- https://git.kernel.org/stable/c/76c2f4d426a5358fced5d5990744d46f10a4ccea
- https://git.kernel.org/stable/c/81cf85ae4f2dd5fa3e43021782aa72c4c85558e8
- https://git.kernel.org/stable/c/936a02b5a9630c5beb0353c3085cc49d86c57034
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html