Junglewise Threat Intelligence

CVE-2024-40958: Linux Kernel use-after-free in netns get_net_ns

CVE-2024-40958 · Severity: high · CVSS 7.8 · Published 2024-07-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem that could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue occurs when the system incorrectly handles network namespaces, which are used to isolate network resources between different processes. This flaw could lead to a 'use-after-free' condition, impacting the overall stability and security of the operating system.

Technical details

A use-after-free vulnerability exists in the Linux kernel's netns component due to improper reference counting in get_net_ns(). The vulnerability is triggered when the TUNGETDEVNETNS ioctl is called on a TUN device that has been moved to a different network namespace that is subsequently deleted. When the ioctl attempts to retrieve the network namespace, get_net_ns() performs a refcount addition on a zeroed reference counter, leading to a kernel warning or panic. An attacker with local access can exploit this race condition to trigger a use-after-free. The fix replaces get_net() with maybe_get_net() to safely handle cases where the namespace's reference count has already reached zero.

Affected products

  • Linux Linux Kernel Fixed in 6.10-rc3 and various stable branches

Timeline

  • 2024-06-14: patched: Initial patch submitted by Yue Haibing
  • 2024-07-12: disclosed: CVE published to NVD

References

Related threats