Executive brief
A vulnerability in the Linux kernel's Network Block Device (NBD) driver could allow a local user to cause a system crash. The issue stems from a missing check when the system attempts to organize network messages, which can lead to a 'null pointer dereference.' This primarily impacts system availability, potentially leading to a denial-of-service condition on affected machines.
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel within the Network Block Device (NBD) driver (drivers/block/nbd.c). The function nbd_genl_status() fails to validate the return value of nla_nest_start_noflag() (or nla_nest_start()). If this function returns NULL due to insufficient buffer space or other failures, the kernel subsequently attempts to dereference the pointer, leading to a kernel oops or crash. This can be triggered by a local user with sufficient privileges to issue NBD generic netlink commands. The fix involves adding a NULL check and returning -EMSGSIZE to properly handle the failure. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4.12 to 5.4.273, 5.5 to 5.10.214, 5.11 to 5.15.153, 5.16 to 6.1.83, 6.2 to 6.6.23, 6.7 to 6.7.11, 6.8 to 6.8.2
Timeline
- 2024-02-18: patched: Initial fix committed to the mainline kernel tree.
- 2024-05-01: disclosed: CVE-2024-27025 published.
References
- https://git.kernel.org/stable/c/31edf4bbe0ba27fd03ac7d87eb2ee3d2a231af6d
- https://git.kernel.org/stable/c/44214d744be32a4769faebba764510888f1eb19e
- https://git.kernel.org/stable/c/4af837db0fd3679fabc7b7758397090b0c06dced
- https://git.kernel.org/stable/c/96436365e5d80d0106ea785a4f80a58e7c9edff8
- https://git.kernel.org/stable/c/98e60b538e66c90b9a856828c71d4e975ebfa797
- https://git.kernel.org/stable/c/b7f5aed55829f376e4f7e5ea5b80ccdcb023e983
- https://git.kernel.org/stable/c/ba6a9970ce9e284cbc04099361c58731e308596a