Junglewise Threat Intelligence

CVE-2024-37356: Linux Kernel shift-out-of-bounds in dctcp_update_alpha

CVE-2024-37356 · Severity: medium · CVSS 5.5 · Published 2024-06-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's TCP implementation could allow a local user to cause a system crash. The issue exists in the Data Center TCP (DCTCP) congestion control module, where certain configuration parameters were not properly validated. By providing an extremely large value to these parameters, an attacker can trigger an internal error that halts the operating system.

Technical details

A shift-out-of-bounds vulnerability exists in net/ipv4/tcp_dctcp.c within the dctcp_update_alpha() function. The root cause is a lack of bounds checking on the 'dctcp_shift_g' module parameter, which is used as a shift exponent. An attacker with local access to modify module parameters (via sysfs) can set 'dctcp_shift_g' to a value (e.g., 100) that exceeds the bit-width of the target 32-bit integer, triggering a kernel panic or undefined behavior. The fix implements a maximum value limit of 10 for this parameter using param_set_uint_minmax().

Affected products

  • Linux Linux Kernel 5.16 to 6.9.4

Timeline

  • 2024-05-17: patched: Initial patch submitted by Kuniyuki Iwashima
  • 2024-06-21: disclosed: CVE published

References

Related threats