Junglewise Threat Intelligence

CVE-2024-36905: Linux Kernel divide by zero in TCP_SYN_RECV socket shutdown

CVE-2024-36905 · Severity: medium · CVSS 5.5 · Published 2024-05-30

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when specific network connection states are handled incorrectly, leading to a system failure (divide-by-zero error). This primarily impacts system availability and could be used to disrupt operations or services running on the affected machine.

Technical details

A divide-by-zero error exists in tcp_rcv_space_adjust() within the Linux kernel's TCP stack. The vulnerability is triggered when a socket in the TCP_SYN_RECV state (often associated with cross-SYN connections) undergoes a shutdown(SEND_SHUTDOWN) transition to TCP_FIN_WAIT1 without having initialized buffer space via tcp_init_transfer(). This bypasses necessary initialization, leading to a division by zero during receive space adjustment. The fix involves deferring the shutdown transition until the socket reaches the TCP_ESTABLISH state. This issue was identified by syzbot and affects multiple stable kernel versions.

Affected products

  • Linux Linux Kernel Fixed in 6.9.0-rc6 and various stable branches

Timeline

  • 2024-05-01: patched: Initial patch authored by Eric Dumazet
  • 2024-05-30: disclosed: CVE published to NVD

References

Related threats