Junglewise Threat Intelligence

CVE-2024-36894: Linux Kernel USB gadget race condition in FunctionFS AIO cancellation

CVE-2024-36894 · Severity: medium · CVSS 5.6 · Published 2024-05-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition vulnerability exists in the Linux kernel's USB gadget driver, which allows devices to act as USB peripherals. When a USB application attempts to cancel an asynchronous data transfer at the same time the hardware is disconnecting, the system may attempt to access memory that has already been freed. This could lead to a system crash or potentially allow an attacker with physical access to the device to compromise the system's stability or access sensitive information.

Technical details

A race condition exists in the Linux kernel USB gadget FunctionFS (f_fs) driver between aio_cancel() and the AIO request completion handler. When a DWC3-based UDC handles a soft disconnect, it triggers a completion routine (ffs_epfile_async_io_complete) that frees the USB request. If an application calls aio_cancel() concurrently, the lack of locking allows the cancellation routine to reference the already-freed request (io_data->req), resulting in a use-after-free (UAF) or stale pointer access. The fix involves moving the request freeing logic to ffs_user_copy_worker() and implementing proper spinlock synchronization using ffs->eps_lock to ensure the request pointer is set to NULL before it can be unsafely accessed. Patching is available across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 3.15 to 4.19.317, 4.20 to 5.4.279, 5.5 to 5.10.221, 5.11 to 5.15.162, 5.16 to 6.1.95, 6.2 to 6.6.31, 6.7 to 6.8.10, 6.9.x up to 6.9-rc6

Timeline

  • 2024-04-08: patched: Initial fix authored by Wesley Cheng
  • 2024-05-30: advisory: CVE-2024-36894 published

References

Related threats