Executive brief
A vulnerability in the Linux kernel's GPRS Tunneling Protocol (GTP) implementation could allow a local user to crash the system or potentially execute unauthorized code. GTP is a protocol used within mobile networks to carry user data between different parts of the core network. An exploit of this flaw could lead to a complete loss of system availability or unauthorized access to sensitive kernel memory.
Technical details
A use-after-free (UAF) vulnerability exists in the gtp_dellink function within the Linux kernel's GTP driver (drivers/net/gtp.c). The issue stems from using hlist_for_each_entry_rcu to traverse the PDP context hash table while calling pdp_context_delete, which internally invokes call_rcu. Because call_rcu is not part of the RCU read critical section, the RCU grace period may expire during traversal, causing the current entry to be freed while the loop is still active. A local attacker with sufficient privileges to manage network interfaces could exploit this to cause a kernel panic or achieve arbitrary code execution. The fix replaces the RCU-based traversal with hlist_for_each_entry_safe to ensure the 'next' pointer is preserved before the current entry is deleted.
Affected products
- Linux Linux Kernel 4.14.162 to 4.15, 4.19.93 to 4.19.313, 5.4.8 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.158, 5.16 to 6.1.90, 6.2 to 6.6.30, 6.7 to 6.8.9
Timeline
- 2024-04-22: patched: Initial fix authored by Hyunwoo Kim
- 2024-05-14: disclosed: CVE published to NVD
References
- https://git.kernel.org/stable/c/07b20d0a3dc13fb1adff10b60021a4924498da58
- https://git.kernel.org/stable/c/0caff3e6390f840666b8dc1ecebf985c2ef3f1dd
- https://git.kernel.org/stable/c/25a1c2d4b1fcf938356a9688a96a6456abd44b29
- https://git.kernel.org/stable/c/2aacd4de45477582993f8a8abb9505a06426bfb6
- https://git.kernel.org/stable/c/2e74b3fd6bf542349758f283676dff3660327c07
- https://git.kernel.org/stable/c/718df1bc226c383dd803397d7f5d95557eb81ac7
- https://git.kernel.org/stable/c/cd957d1716ec979d8f5bf38fc659aeb9fdaa2474