Junglewise Threat Intelligence

CVE-2024-35886: Linux kernel infinite recursion in IPv6 fib6_dump_done

CVE-2024-35886 · Severity: high · CVSS 7.8 · Published 2024-05-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's IPv6 networking component could allow a local user to crash the system. The issue occurs when the system handles specific network routing requests and encounters a memory allocation failure, leading to an infinite loop that exhausts system resources. This can result in a complete system denial of service, impacting availability and ongoing operations.

Technical details

An infinite recursion vulnerability exists in the Linux kernel's IPv6 Forwarding Information Base (FIB) dumping mechanism. The root cause is located in 'net/ipv6/ip6_fib.c' where 'fib6_dump_done()' is assigned as a callback destructor before a memory allocation ('kzalloc') occurs. If the allocation fails (e.g., due to fault injection or memory pressure), the callback state is left in a circular reference where 'fib6_dump_done()' eventually calls itself recursively via 'nlk_sk(sk)->cb.done()'. This leads to a stack overflow and a kernel panic (hitting the stack guard page). An attacker with local access can trigger this by sending specific Netlink messages ('AF_UNSPEC RTM_GETROUTE') and interrupting the response. Patches have been released across multiple stable kernel branches to reorder the destructor assignment after successful memory allocation.

Affected products

  • Linux Linux kernel All versions from 2.6.12-rc2 up to fixed versions in 6.8.x, 6.6.x, 6.1.x, 5.15.x, 5.10.x, 5.4.x, 4.19.x, and 4.14.x

Timeline

  • 2024-04-01: disclosed: Initial patch submission by Kuniyuki Iwashima
  • 2024-04-10: patched: Patches committed to stable kernel trees
  • 2024-05-19: advisory: CVE-2024-35886 published

References

Related threats