Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash. The issue exists in the 'geneve' driver, which is used for virtualized networking (tunneling). By sending specifically crafted network packets, an attacker can trigger an error that leads to the use of uninitialized memory, resulting in a denial-of-service condition.
Technical details
A use of uninitialized resource vulnerability (CWE-908) exists in the geneve driver (drivers/net/geneve.c) within the geneve_xmit() and geneve6_xmit_skb() functions. The root cause is that pskb_inet_may_pull() relies on skb->protocol; if a caller (such as af_packet) provides a VLAN tag, the protocol field may not reflect ETH_P_IP or ETH_P_IPV6, causing header validation to be skipped. This results in the network header pointing to an incorrect location and the linear part of the socket buffer (skb) being smaller than expected. A local attacker can exploit this to trigger an uninitialized-value error, leading to a kernel panic or denial of service. The fix introduces skb_vlan_inet_prepare() to ensure proper MAC and network header validation.
Affected products
- Linux Linux Kernel 4.19.191 to 4.19.313, 5.16 to 6.1.87, 6.2 to 6.6.28, 6.7 to 6.8.7, 6.9-rc1 to 6.9-rc3
Timeline
- 2024-04-05: patched: Initial patch submitted by Eric Dumazet
- 2024-05-20: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/10204df9beda4978bd1d0c2db0d8375bfb03b915
- https://git.kernel.org/stable/c/190d9efa5773f26d6f334b1b8be282c4fa13fd5e
- https://git.kernel.org/stable/c/357163fff3a6e48fe74745425a32071ec9caf852
- https://git.kernel.org/stable/c/3c1ae6de74e3d2d6333d29a2d3e13e6094596c79
- https://git.kernel.org/stable/c/43be590456e1f3566054ce78ae2dbb68cbe1a536
- https://git.kernel.org/stable/c/4a1b65d1e55d53b397cb27014208be1e04172670
- https://git.kernel.org/stable/c/d3adf11d7993518a39bd02b383cfe657ccc0023c