Junglewise Threat Intelligence

CVE-2024-36904: Linux Kernel use-after-free in tcp_twsk_unique

CVE-2024-36904 · Severity: high · CVSS 7.8 · Published 2024-05-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash or potentially execute unauthorized code. The issue occurs during specific network connection processes where the system incorrectly manages memory for sockets in a 'TIME-WAIT' state. This could lead to a 'use-after-free' condition, impacting the overall stability and security of the operating system.

Technical details

A use-after-free vulnerability exists in the Linux kernel's tcp_twsk_unique() function. The root cause is a race condition introduced by a previous optimization in inet_twsk_hashdance(), which sets a TIME-WAIT socket's reference count after it has been added to the hash table and the bucket lock has been released. During this window, a concurrent connect() call can attempt to reuse the port and call sock_hold() on a socket with a zero reference count. This leads to reference count underflow and a subsequent use-after-free. The fix replaces sock_hold() with refcount_inc_not_zero() to safely handle sockets that are not yet fully initialized or are being decommissioned.

Affected products

  • Linux Linux Kernel 6.9-rc1 through 6.9-rc4, and various stable branches

Timeline

  • 2024-05-01: patched: Initial patch submitted by Kuniyuki Iwashima
  • 2024-05-30: disclosed: CVE-2024-36904 published

References

Related threats