Executive brief
A vulnerability in the Linux kernel's Netfilter component could allow a local user to cause a system crash. Netfilter is a framework that provides various network-related operations like packet filtering and NAT. By providing specially crafted input, an attacker can trigger an unsafe memory operation, leading to a denial-of-service condition.
Technical details
A vulnerability exists in the Linux kernel Netfilter subsystem due to insufficient validation of user-supplied length (@optlen) in the do_replace() handlers within arp_tables.c, ip_tables.c, and ip6_tables.c. While previous fixes addressed copy_from_sockptr(), subsequent calls to copy_from_sockptr_offset() remained unsafe. A local attacker with low privileges can exploit this by providing a length value that is smaller than the expected structure size, potentially leading to out-of-bounds memory access or a kernel panic (DoS). The fix introduces a explicit check to ensure the provided length is at least the size of the expected header plus the reported table size before proceeding with allocation and copying.
Affected products
- Linux Linux Kernel 5.10.215, 5.15.154 to 5.15.156, 6.1.85 to 6.1.87, 6.6.26 to 6.6.28, 6.8.5 to 6.8.7, 6.9-rc3
Timeline
- 2024-04-09: patched: Initial patch authored by Eric Dumazet
- 2024-05-20: disclosed: CVE published
References
- https://git.kernel.org/stable/c/562b7245131f6e9f1d280c8b5a8750f03edfc05c
- https://git.kernel.org/stable/c/65acf6e0501ac8880a4f73980d01b5d27648b956
- https://git.kernel.org/stable/c/89242d9584c342cb83311b598d9e6b82572eadf8
- https://git.kernel.org/stable/c/97dab36e57c64106e1c8ebd66cbf0d2d1e52d6b7
- https://git.kernel.org/stable/c/c760089aa98289b4b88a7ff5a62dd92845adf223
- https://git.kernel.org/stable/c/cf4bc359b76144a3dd55d7c09464ef4c5f2b2b05
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html