Executive brief
A vulnerability in the Linux kernel's NET/ROM protocol implementation could allow a local user to cause a system instability or denial of service. The issue stems from a race condition where system configuration values are read and modified simultaneously. This could lead to unpredictable behavior in network packet handling, potentially crashing the affected service.
Technical details
A race condition (CWE-362) exists in the netrom implementation within the Linux kernel, specifically involving the sysctl_netrom_reset_circuit value (referred to as sysctl_net_busy_read in some contexts). The vulnerability occurs because the kernel reads this sysctl value without proper synchronization while it can be concurrently modified. An attacker with local access could exploit this data race to trigger inconsistent state transitions in the NET/ROM state machine (nr_state1_machine, nr_state2_machine, nr_state3_machine), potentially leading to a denial of service. The fix introduces READ_ONCE() macros to ensure atomic reads of the configuration value.
Affected products
- Linux Linux Kernel 2.6.12-rc2 to 4.19.310, 4.20 to 5.4.272, 5.5 to 5.10.213, 5.11 to 5.15.152, 5.16 to 6.1.82, 6.2 to 6.6.22, 6.7 to 6.7.10
Timeline
- 2024-03-15: patched: Fix committed to stable kernel trees.
- 2024-05-17: disclosed: CVE-2024-27419 published.
References
- https://git.kernel.org/stable/c/0866afaff19d8460308b022345ed116a12b1d0e1
- https://git.kernel.org/stable/c/16d71319e29d5825ab53f263b59fdd8dc2d60ad4
- https://git.kernel.org/stable/c/34cab94f7473e7b09f5205d4583fb5096cb63b5b
- https://git.kernel.org/stable/c/43464808669ba9d23996f0b6d875450191687caf
- https://git.kernel.org/stable/c/bbf950a6e96a91cf8cf0c71117b94ed3fafc9dd3
- https://git.kernel.org/stable/c/d380ce70058a4ccddc3e5f5c2063165dc07672c6
- https://git.kernel.org/stable/c/d623fd5298d95b65d27ef5a618ebf39541074856