Junglewise Threat Intelligence

CVE-2024-35962: Linux Kernel Netfilter insufficient input validation in do_replace

CVE-2024-35962 · Severity: medium · CVSS 5.5 · Published 2024-05-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Netfilter component could allow a local user to cause a system crash. Netfilter is a framework that provides various network-related operations like packet filtering and NAT. By providing specially crafted input, an attacker can trigger an unsafe memory operation, leading to a denial-of-service condition.

Technical details

A vulnerability exists in the Linux kernel Netfilter subsystem due to insufficient validation of user-supplied length (@optlen) in the do_replace() handlers within arp_tables.c, ip_tables.c, and ip6_tables.c. While previous fixes addressed copy_from_sockptr(), subsequent calls to copy_from_sockptr_offset() remained unsafe. A local attacker with low privileges can exploit this by providing a length value that is smaller than the expected structure size, potentially leading to out-of-bounds memory access or a kernel panic (DoS). The fix introduces a explicit check to ensure the provided length is at least the size of the expected header plus the reported table size before proceeding with allocation and copying.

Affected products

  • Linux Linux Kernel 5.10.215, 5.15.154 to 5.15.156, 6.1.85 to 6.1.87, 6.6.26 to 6.6.28, 6.8.5 to 6.8.7, 6.9-rc3

Timeline

  • 2024-04-09: patched: Initial patch authored by Eric Dumazet
  • 2024-05-20: disclosed: CVE published

References

Related threats