Executive brief
A vulnerability was identified in the Linux kernel's networking subsystem that could allow a local user to cause a system crash or potentially execute unauthorized code. The issue exists in the component responsible for managing multiple network transmission queues. An exploit could compromise the integrity of the operating system or lead to a complete service outage.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the multiq_tune() function within net/sched/sch_multiq.c of the Linux kernel. The root cause is an incorrect memory allocation calculation where the kernel used an outdated value for 'q->bands' during kmalloc() instead of the updated 'qopt->bands' value. A local attacker with low privileges can exploit this flaw to overwrite adjacent kernel memory. This can result in a kernel panic (Denial of Service) or potentially be leveraged for local privilege escalation. The issue has been patched in multiple stable branches including 5.4.279, 5.10.221, 5.15.162, 6.1.95, 6.6.35, and 6.9.6.
Affected products
- Linux Linux Kernel 5.4 to 5.4.279, 5.5 to 5.10.221, 5.11 to 5.15.162, 5.16 to 6.1.95, 6.2 to 6.6.35, 6.7 to 6.9.6
Timeline
- 2024-06-03: patched: Initial patch submitted to the Linux kernel mailing list
- 2024-06-19: disclosed: CVE published to NVD
- 2024-08-19: advisory: NVD analysis completed
References
- https://git.kernel.org/stable/c/0f208fad86631e005754606c3ec80c0d44a11882
- https://git.kernel.org/stable/c/52b1aa07cda6a199cd6754d3798c7759023bc70f
- https://git.kernel.org/stable/c/54c2c171c11a798fe887b3ff72922aa9d1411c1e
- https://git.kernel.org/stable/c/598572c64287aee0b75bbba4e2881496878860f3
- https://git.kernel.org/stable/c/affc18fdc694190ca7575b9a86632a73b9fe043d
- https://git.kernel.org/stable/c/d5d9d241786f49ae7cbc08e7fc95a115e9d80f3d
- https://git.kernel.org/stable/c/d6fb5110e8722bc00748f22caeb650fe4672f129