Executive brief
A vulnerability in the Linux kernel's kprobes component could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs when the system attempts to register a probe on a software module that is simultaneously being unloaded. This race condition can lead to memory corruption, impacting the overall stability and security of the operating system.
Technical details
A use-after-free (UAF) vulnerability exists in kernel/kprobes.c due to a race condition in check_kprobe_address_safe(). The function previously used separate calls to is_module_text_address() and __module_text_address(). If a module's state transitions to MODULE_STATE_UNFORMED between these two calls during unloading, the second call may fail or return an invalid reference. Consequently, arm_kprobe() may attempt to modify a non-existent or freed module text address. The fix consolidates these checks into a single __module_text_address() call followed by try_module_get() to ensure the module remains valid during registration. This issue affects multiple stable kernel branches and has been patched in versions including 6.8.7, 6.6.28, and various LTS releases.
Affected products
- Linux Linux Kernel 4.14.291 to 4.15; 4.19.256 to 4.19.313; 5.4.211 to 5.4.275; 5.10.137 to 5.10.216; 5.15.61 to 5.15.157; 5.18.18 to 5.19; 5.19.2 to 6.1.87; 6.2 to 6.6.28; 6.7 to 6.8.7; 6.9-rc1 to 6.9-rc3
Timeline
- 2024-04-10: patched: Initial patch submitted by Zheng Yejian
- 2024-05-20: advisory: CVE-2024-35955 published
References
- https://git.kernel.org/stable/c/2df2dd27066cdba8041e46a64362325626bdfb2e
- https://git.kernel.org/stable/c/325f3fb551f8cd672dbbfc4cf58b14f9ee3fc9e8
- https://git.kernel.org/stable/c/36b57c7d2f8b7de224980f1a284432846ad71ca0
- https://git.kernel.org/stable/c/5062d1f4f07facbdade0f402d9a04a788f52e26d
- https://git.kernel.org/stable/c/62029bc9ff2c17a4e3a2478d83418ec575413808
- https://git.kernel.org/stable/c/93eb31e7c3399e326259f2caa17be1e821f5a412
- https://git.kernel.org/stable/c/b5808d40093403334d939e2c3c417144d12a6f33