Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs during specific network connection processes where the system incorrectly manages memory for sockets in a 'TIME-WAIT' state. This could lead to a 'use-after-free' condition, impacting the overall stability and security of the operating system.
Technical details
A use-after-free vulnerability exists in the Linux kernel's tcp_twsk_unique() function. The root cause is a race condition introduced by a previous optimization in inet_twsk_hashdance(), which sets a TIME-WAIT socket's reference count after it has been added to the hash table and the bucket lock has been released. During this window, a concurrent connect() call can attempt to reuse the port and call sock_hold() on a socket with a zero reference count. This leads to reference count underflow and a subsequent use-after-free. The fix replaces sock_hold() with refcount_inc_not_zero() to safely handle sockets that are not yet fully initialized or are being decommissioned.
Affected products
- Linux Linux Kernel 6.9-rc1 through 6.9-rc4, and various stable branches
Timeline
- 2024-05-01: patched: Initial patch submitted by Kuniyuki Iwashima
- 2024-05-30: disclosed: CVE-2024-36904 published
References
- https://git.kernel.org/stable/c/13ed7cdf079686ccd3618335205700c03f6fb446
- https://git.kernel.org/stable/c/1796ca9c6f5bd50554214053af5f47d112818ee3
- https://git.kernel.org/stable/c/1d9cf07810c30ef7948879567d10fd1f01121d34
- https://git.kernel.org/stable/c/27b0284d8be182a81feb65581ab6a724dfd596e8
- https://git.kernel.org/stable/c/517e32ea0a8c72202d0d8aa8df50a7cd3d6fdefc
- https://git.kernel.org/stable/c/6e48faad92be13166184d21506e4e54c79c13adc
- https://git.kernel.org/stable/c/84546cc1aeeb4df3e444b18a4293c9823f974be9