Junglewise Threat Intelligence

CVE-2024-27395: Linux Kernel use-after-free in Open vSwitch ovs_ct_exit

CVE-2024-27395 · Severity: high · CVSS 7.8 · Published 2024-05-14

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability has been identified in the Linux kernel's Open vSwitch component, which is used for virtual networking. A flaw in how the system cleans up network connection tracking limits could allow a local attacker to cause a system crash or potentially execute unauthorized actions. This issue primarily affects the stability and security of virtualized environments and software-defined networks.

Technical details

A use-after-free (UAF) vulnerability exists in the Open vSwitch (OVS) conntrack implementation within the Linux kernel. The root cause is located in the ovs_ct_limit_exit function, where kfree_rcu is invoked during an hlist_for_each_entry_rcu traversal. Because this traversal is not protected by an RCU read critical section, an RCU grace period can expire during the loop, leading to the underlying data structure being freed while still being accessed. An attacker with local access could exploit this race condition to trigger a kernel crash or achieve arbitrary code execution. The fix involves replacing the RCU-specific iterator with hlist_for_each_entry_safe to ensure safe traversal during deletion.

Affected products

  • Linux Linux Kernel 4.18 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.157, 5.16 to 6.1.89, 6.2 to 6.6.29, 6.7 to 6.8.8

Timeline

  • 2024-04-24: patched: Initial fix committed to mainline kernel
  • 2024-05-14: disclosed: CVE published

References

Related threats