Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash. The issue occurs when specific network socket operations are performed in an unexpected order, leading to an internal kernel error (splat). This primarily impacts system availability and could be used to disrupt operations or services running on the affected host.
Technical details
A vulnerability exists in the Linux kernel's af_inet.c component due to overly restrictive socket state assertions during the accept() system call. When a reproducer invokes shutdown() before a socket enters the listener status, a child socket can reach the __inet_accept() function in the FIN_WAIT1 state. This triggers a WARN_ON assertion because FIN_WAIT1 was not previously considered a valid state for a socket being accepted. An attacker with local access can exploit this to trigger kernel warnings or potential instability. The fix involves relaxing the state check in __inet_accept() to include FIN_WAIT1, FIN_WAIT2, and CLOSING states.
Affected products
- Linux Linux Kernel 4.19.314 to 4.19.319, 5.4.276 to 5.4.281, 5.10.217 to 5.10.223, 5.15.159 to 5.15.164, 6.1.91 to 6.1.93, 6.6.31 to 6.6.33, 6.8.10 to 6.9.4
Timeline
- 2024-05-21: patched: Initial patch authored by Paolo Abeni
- 2024-06-21: advisory: CVE published
References
- https://git.kernel.org/stable/c/21c14c556cccd0cb54b71ec5e901e64ba84c7165
- https://git.kernel.org/stable/c/26afda78cda3da974fd4c287962c169e9462c495
- https://git.kernel.org/stable/c/59801e88c99f7c3f44a4d20af6ba6417aa359b5d
- https://git.kernel.org/stable/c/5f9a04a94fd1894d7009055ab8e5832a0242dba3
- https://git.kernel.org/stable/c/6e03006548c66b979f4e5e9fc797aac4dad82822
- https://git.kernel.org/stable/c/7de00adc9bd035d861ba4177848ca0bfa5ed1e04
- https://git.kernel.org/stable/c/87bdc9f6f58b4417362d6932b49b828e319f97dc