Executive brief
A vulnerability in the Linux kernel's networking component could allow local users to cause system instability. The issue occurs when the system processes network traffic using a specific high-performance feature called XDP with cpumap. This can lead to the system using uninitialized memory, potentially resulting in unpredictable behavior or a system crash.
Technical details
A 'Use of Uninitialized Resource' vulnerability (CWE-908) exists in the Linux kernel's cpumap component. When an XDP program is attached to a cpumap entry, the xdp_rxq_info structure within the xdp_buff is not initialized. This causes the xdp_md->rx_queue_index value to return random data from uninitialized memory. A local attacker could potentially leverage this to cause a denial of service or observe sensitive memory contents, though the reported impact is primarily on availability. The issue has been resolved by zero-initializing the rxq data structure in kernel/bpf/cpumap.c.
Affected products
- Linux Linux Kernel versions from 5.9 up to (excluding) 5.10.213; versions from 5.11 up to (excluding) 5.15.152; versions from 5.16 up to (excluding) 6.1.82; versions from 6.2 up to (excluding) 6.6.22; versions from 6.7 up to (excluding) 6.7.10; 6.8-rc1 through 6.8-rc7
Timeline
- 2024-03-05: patched: Initial fix committed to mainline kernel
- 2024-05-17: disclosed: CVE published
References
- https://git.kernel.org/stable/c/2487007aa3b9fafbd2cb14068f49791ce1d7ede5
- https://git.kernel.org/stable/c/3420b3ff1ff489c177ea1cb7bd9fbbc4e9a0be95
- https://git.kernel.org/stable/c/5f4e51abfbe6eb444fa91906a5cd083044278297
- https://git.kernel.org/stable/c/eaa7cb836659ced2d9f814ac32aa3ec193803ed6
- https://git.kernel.org/stable/c/f0363af9619c77730764f10360e36c6445c12f7b
- https://git.kernel.org/stable/c/f562e4c4aab00986dde3093c4be919c3f2b85a4a
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html