Junglewise Threat Intelligence

CVE-2024-35960: Linux Kernel mlx5 NULL pointer dereference in net/mlx5

CVE-2024-35960 · Severity: critical · CVSS 9.1 · Published 2024-05-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Mellanox network driver can cause a system crash. The issue occurs when the system incorrectly manages internal networking rules, leading to a memory error when those rules are deleted. This could potentially be used to disrupt network services or cause a denial-of-service (DoS) condition on affected servers.

Technical details

A NULL pointer dereference vulnerability exists in the net/mlx5 driver of the Linux kernel due to improper linking of flow steering (fs) rules into the internal tree structure. The function add_rule_fg previously only added rules to the tree if they had a reference count of 1. However, create_flow_handle could create a new rule and reference it multiple times during a single handle creation, resulting in a reference count greater than 1 for a rule not yet linked to the tree. When such a rule is later deleted, the del_sw_hw_rule function attempts to access a NULL parent pointer, causing a kernel panic. This issue has been resolved by ensuring new rules are linked into the tree based on the absence of a parent pointer rather than the reference count.

Affected products

  • Linux Linux Kernel 4.10 to 4.19.313, 4.20 to 5.4.275, 5.5 to 5.10.216, 5.11 to 5.15.156, 5.16 to 6.1.87, 6.2 to 6.6.28, 6.7 to 6.8.7

Timeline

  • 2024-05-20: advisory: Initial publication of the CVE record
  • 2024-05-02: patched: Fix committed to the Linux stable kernel tree

References

Related threats