Executive brief
A vulnerability was identified in the Linux kernel's SUNRPC component, which handles network communication for services like file sharing. A flaw in how the system manages memory during certain security token operations could allow a local user to cause a system crash. This impact is primarily on system availability, potentially leading to a denial-of-service condition on affected servers.
Technical details
A vulnerability exists in the SUNRPC GSS (Generic Security Services) implementation within the Linux kernel. The root cause is a missing NULL terminator in the 'in_token->pages[]' array, which is used during the processing of security tokens. When 'gss_free_in_token_pages()' attempts to iterate through this array, the lack of a termination condition results in an out-of-bounds or wild memory access, as evidenced by KASAN (Kernel Address Sanitizer) reports. This is classified as CWE-835 (Loop with Unreachable Exit Condition). An attacker with local access could trigger this condition to cause a kernel panic (DoS). The issue has been patched in various stable branches by ensuring 'kcalloc' allocates an additional slot for the NULL terminator.
Affected products
- Linux Linux Kernel up to 6.9.4, 6.10.0-rc1
Timeline
- 2024-06-02: patched: Initial patch authored by Chuck Lever
- 2024-06-21: disclosed: CVE-2024-36288 published
References
- https://git.kernel.org/stable/c/0a1cb0c6102bb4fd310243588d39461da49497ad
- https://git.kernel.org/stable/c/4a77c3dead97339478c7422eb07bf4bf63577008
- https://git.kernel.org/stable/c/4cefcd0af7458bdeff56a9d8dfc6868ce23d128a
- https://git.kernel.org/stable/c/57ff6c0a175930856213b2aa39f8c845a53e5b1c
- https://git.kernel.org/stable/c/6ed45d20d30005bed94c8c527ce51d5ad8121018
- https://git.kernel.org/stable/c/af628d43a822b78ad8d4a58d8259f8bf8bc71115
- https://git.kernel.org/stable/c/b4878ea99f2b40ef1925720b1b4ca7f4af1ba785