Junglewise Threat Intelligence

CVE-2024-35955: Linux Kernel use-after-free in kprobes registration

CVE-2024-35955 · Severity: high · CVSS 8.8 · Published 2024-05-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's kprobes component could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system attempts to register a probe on a software module that is simultaneously being unloaded. This race condition can lead to memory corruption, impacting the overall stability and security of the operating system.

Technical details

A use-after-free (UAF) vulnerability exists in kernel/kprobes.c due to a race condition in check_kprobe_address_safe(). The function previously used separate calls to is_module_text_address() and __module_text_address(). If a module's state transitions to MODULE_STATE_UNFORMED between these two calls during unloading, the second call may fail or return an invalid reference. Consequently, arm_kprobe() may attempt to modify a non-existent or freed module text address. The fix consolidates these checks into a single __module_text_address() call followed by try_module_get() to ensure the module remains valid during registration. This issue affects multiple stable kernel branches and has been patched in versions including 6.8.7, 6.6.28, and various LTS releases.

Affected products

  • Linux Linux Kernel 4.14.291 to 4.15; 4.19.256 to 4.19.313; 5.4.211 to 5.4.275; 5.10.137 to 5.10.216; 5.15.61 to 5.15.157; 5.18.18 to 5.19; 5.19.2 to 6.1.87; 6.2 to 6.6.28; 6.7 to 6.8.7; 6.9-rc1 to 6.9-rc3

Timeline

  • 2024-04-10: patched: Initial patch submitted by Zheng Yejian
  • 2024-05-20: advisory: CVE-2024-35955 published

References

Related threats