Junglewise Threat Intelligence

CVE-2024-35976: Linux Kernel out-of-bounds write in xsk_setsockopt

CVE-2024-35976 · Severity: medium · CVSS 6.7 · Published 2024-05-20

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was found in the Linux kernel's networking component that handles high-performance data transfer. A local user could potentially trigger an illegal memory access, which might lead to system instability or unauthorized access to sensitive information. This issue has been addressed by improving how the system validates user-provided data during network configuration.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in net/xdp/xsk.c within the Linux kernel. The function xsk_setsockopt() fails to properly validate the @optlen parameter when handling XDP_UMEM_FILL_RING or XDP_COMPLETION_FILL_RING options. This lack of validation allows a local attacker to trigger an illegal memory copy via copy_from_sockptr(), leading to a slab-out-of-bounds access as reported by syzbot. The vulnerability is reachable via the setsockopt() system call. Patches have been released across multiple stable kernel branches to enforce strict length validation.

Affected products

  • Linux Linux Kernel 6.8.0-syzkaller-08951-gfe46a7dd189e and earlier versions

Timeline

  • 2024-04-04: patched: Initial patch authored by Eric Dumazet
  • 2024-05-20: disclosed: CVE published to NVD

References

Related threats