Junglewise Threat Intelligence

CVE-2024-36288: Linux Kernel SUNRPC wild memory access in gss_free_in_token_pages

CVE-2024-36288 · Severity: medium · CVSS 5.5 · Published 2024-06-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's SUNRPC component, which handles network communication for services like file sharing. A flaw in how the system manages memory during certain security token operations could allow a local user to cause a system crash. This impact is primarily on system availability, potentially leading to a denial-of-service condition on affected servers.

Technical details

A vulnerability exists in the SUNRPC GSS (Generic Security Services) implementation within the Linux kernel. The root cause is a missing NULL terminator in the 'in_token->pages[]' array, which is used during the processing of security tokens. When 'gss_free_in_token_pages()' attempts to iterate through this array, the lack of a termination condition results in an out-of-bounds or wild memory access, as evidenced by KASAN (Kernel Address Sanitizer) reports. This is classified as CWE-835 (Loop with Unreachable Exit Condition). An attacker with local access could trigger this condition to cause a kernel panic (DoS). The issue has been patched in various stable branches by ensuring 'kcalloc' allocates an additional slot for the NULL terminator.

Affected products

  • Linux Linux Kernel up to 6.9.4, 6.10.0-rc1

Timeline

  • 2024-06-02: patched: Initial patch authored by Chuck Lever
  • 2024-06-21: disclosed: CVE-2024-36288 published

References

Related threats