Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to access sensitive information from the system's memory. This occurs because certain internal data structures were not properly cleared before being sent to user-level applications. While the leaked data is small (four bytes), it could potentially contain fragments of sensitive kernel information.
Technical details
A kernel information leak exists in the net/sched/act_skbmod.c component of the Linux kernel. The function tcf_skbmod_dump() fails to initialize a 'struct tc_skbmod' structure, which contains a four-byte padding hole. When this structure is copied to user space via Netlink, these four uninitialized bytes from the kernel stack are leaked. An attacker with local access can exploit this to read small amounts of kernel stack memory. The issue has been resolved by explicitly clearing the structure before populating its fields.
Affected products
- Linux Linux Kernel 6.9-rc1
Timeline
- 2024-04-03: patched: Initial patch submitted by Eric Dumazet
- 2024-05-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/55d3fe7b2b7bc354e7cbc1f7b8f98a29ccd5a366
- https://git.kernel.org/stable/c/5e45dc4408857305f4685abfd7a528a1e58b51b5
- https://git.kernel.org/stable/c/729ad2ac2a2cdc9f4a4bdfd40bfd276e6bc33924
- https://git.kernel.org/stable/c/7bb2c7103d8c13b06a57bf997b8cdbe93cd7283c
- https://git.kernel.org/stable/c/a097fc199ab5f4b5392c5144034c0d2148b55a14
- https://git.kernel.org/stable/c/d313eb8b77557a6d5855f42d2234bd592c7b50dd
- https://git.kernel.org/stable/c/f190a4aa03cbd518bd9c62a66e1233984f5fd2ec