Junglewise Threat Intelligence

CVE-2024-33621: Linux Kernel DoS in IPVLAN outbound packet processing

CVE-2024-33621 · Severity: medium · CVSS 5.5 · Published 2024-06-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IPVLAN driver could allow a local user to cause a system crash. IPVLAN is a driver used to create virtual network interfaces, often used in container environments. By sending specific types of network traffic, an attacker can trigger an internal error (kernel panic) that disrupts the availability of the host system.

Technical details

A vulnerability exists in the Linux kernel's ipvlan driver within the ipvlan_process_v4_outbound and ipvlan_process_v6_outbound functions. When a raw packet is sent from a PF_PACKET socket over an IPv6-backed ipvlan device, the kernel incorrectly attempts to use the socket associated with the packet (skb->sk) during the transmission path. This triggers a WARN_ON_ONCE() in sk_mc_loop() because the socket family (AF_PACKET) is unexpected in that context. An attacker with local access can exploit this to trigger kernel warnings or potential denial-of-service conditions. The fix involves passing a NULL socket pointer to the ip_local_out and ip6_local_out functions, consistent with how other tunnel drivers operate.

Affected products

  • Linux Linux Kernel 3.19 to 4.19.316, 4.20 to 5.4.278, 5.5 to 5.10.219, 5.11 to 5.15.161, 5.16 to 6.1.93, 6.2 to 6.6.33, 6.7 to 6.9.4

Timeline

  • 2024-05-29: patched: Initial patch submitted by Yue Haibing
  • 2024-06-21: advisory: CVE-2024-33621 published

References

Related threats