Executive brief
A vulnerability exists in the Linux kernel's networking subsystem, specifically within the netfilter framework used for firewalling and traffic management. A race condition could allow a local user to cause a system crash or instability by triggering concurrent operations during the registration or lookup of network flow tables. This primarily impacts the availability of the system.
Technical details
A race condition exists in the nf_tables component of the Linux kernel due to improper synchronization when accessing the nf_tables_flowtables list. Specifically, nft_unregister_flowtable_type() can run concurrently with __nft_flowtable_type_get() without adequate protection during list iteration. An attacker with local access could exploit this data race to cause a kernel panic or other unpredictable behavior. The fix involves implementing RCU (Read-Copy-Update) primitives, specifically using list_for_each_entry_rcu() and rcu_read_lock(), to ensure thread-safe access to the flowtable list during type query processes. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux kernel 4.16 to 4.19.312, 4.20 to 5.4.274, 5.5 to 5.10.215, 5.11 to 5.15.154, 5.16 to 6.1.85, 6.2 to 6.6.26, 6.7 to 6.8.5, 6.9-rc1, 6.9-rc2
Timeline
- 2024-04-03: patched: Initial patch authored by Ziyang Xuan
- 2024-05-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/24225011d81b471acc0e1e315b7d9905459a6304
- https://git.kernel.org/stable/c/2485bcfe05ee3cf9ca8923a94fa2e456924c79c8
- https://git.kernel.org/stable/c/69d1fe14a680042ec913f22196b58e2c8ff1b007
- https://git.kernel.org/stable/c/8b891153b2e4dc0ca9d9dab8f619d49c740813df
- https://git.kernel.org/stable/c/940d41caa71f0d3a52df2fde5fada524a993e331
- https://git.kernel.org/stable/c/9b5b7708ec2be21dd7ef8ca0e3abe4ae9f3b083b
- https://git.kernel.org/stable/c/a347bc8e6251eaee4b619da28020641eb5b0dd77