Junglewise Threat Intelligence

CVE-2024-36899: Linux Kernel use after free in gpiolib lineinfo_changed_notify

CVE-2024-36899 · Severity: high · CVSS 7 · Published 2024-05-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's GPIO (General Purpose Input/Output) subsystem, which manages how the operating system interacts with hardware pins. A race condition during the closing of a hardware device file could allow a local attacker to trigger a 'use-after-free' error. While the primary impact is a potential system crash or instability, such flaws can sometimes be leveraged to gain unauthorized access or escalate privileges on the affected system.

Technical details

A use-after-free vulnerability exists in the Linux kernel's gpiolib-cdev component due to a race condition between gpio_chrdev_release() and lineinfo_changed_notify(). When a GPIO chip device file is closed, the 'watched_lines' bitmap is freed before the 'lineinfo_changed_nb' notifier chain is successfully unregistered. If a GPIO line event occurs simultaneously, the notifier chain may attempt to access the already-freed bitmap. This requires local access and specific timing to exploit. The issue has been resolved by reordering the release sequence to ensure the notifier chain is unregistered before the bitmap is freed. Fixes are available in stable kernel versions 6.6.31, 6.8.10, and 6.9.

Affected products

  • Linux Linux Kernel 5.7 to 6.6.30, 6.7 to 6.8.9, 6.9-rc1 to 6.9-rc7

Timeline

  • 2024-05-05: other: Initial patch submitted
  • 2024-05-30: advisory: CVE-2024-36899 published

References

Related threats