Junglewise Threat Intelligence

CVE-2024-35900: Linux Kernel nf_tables denial of service via inconsistent table state

CVE-2024-35900 · Severity: medium · CVSS 5.5 · Published 2024-05-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a system crash. The issue exists in the 'nf_tables' component, which manages firewall rules and network filtering. By providing a specific sequence of configuration commands, an attacker can trigger an internal inconsistency that leads to a kernel warning or failure, impacting the availability of the system.

Technical details

A vulnerability exists in the Linux kernel netfilter subsystem (nf_tables) due to improper handling of basechain additions during table flag updates. When the 'dormant' flag is toggled, hooks are disabled in the commit phase by iterating over current chains. However, the system allowed adding a new basechain after a dormant flag update but before the commit phase was finalized, leading to an inconsistent state where the kernel attempts to unregister a hook that was never properly registered. This triggers a kernel WARNING in __nf_unregister_net_hook. The fix involves rejecting new basechain additions if the table is currently undergoing a flag update (__NFT_TABLE_F_UPDATE). This is a local attack vector requiring low privileges.

Affected products

  • Linux Linux Kernel 5.4.262 to 5.4.274, 5.10.202 to 5.10.215, 5.13.1 to 5.15.154, 5.16 to 6.1.85, 6.2 to 6.6.26, 6.7 to 6.8.5

Timeline

  • 2024-04-08: patched: Initial patch by Pablo Neira Ayuso
  • 2024-05-19: disclosed: CVE published

References

Related threats