Executive brief
A vulnerability in the Linux kernel's network drop monitor component could allow a local user to cause a system crash or instability. This issue specifically affects systems running Real-Time (RT) kernel configurations, where certain internal locking mechanisms behave differently. An exploit could lead to a denial-of-service, impacting the availability of the affected server or device.
Technical details
A locking issue exists in the Linux kernel's drop_monitor component, specifically within the trace_drop_common() function. In Real-Time (RT) kernel configurations, standard spin_locks are converted into sleeping locks. Because trace_drop_common() is called with preemption disabled (atomic context), acquiring a sleeping spin_lock triggers a 'sleeping function called from invalid context' error (kernel splat). This vulnerability is categorized under CWE-667 (Improper Locking). An attacker with local access could potentially trigger this condition to cause a denial-of-service. The fix involves replacing the standard spin_lock with a raw_spin_lock to ensure the lock does not sleep, maintaining compatibility with RT kernel requirements.
Affected products
- Linux Linux Kernel up to 5.4.279, 5.5 to 5.10.221, 5.11 to 5.15.162, 5.16 to 6.1.96, 6.2 to 6.6.36
Timeline
- 2024-07-12: advisory: NVD publication date
- 2024-06-27: patched: Fix committed to stable kernel tree
References
- https://git.kernel.org/stable/c/07ea878684dfb78a9d4f564c39d07e855a9e242e
- https://git.kernel.org/stable/c/594e47957f3fe034645e6885393ce96c12286334
- https://git.kernel.org/stable/c/76ce2f9125244e1708d29c1d3f9d1d50b347bda0
- https://git.kernel.org/stable/c/96941f29ebcc1e9cbf570dc903f30374909562f5
- https://git.kernel.org/stable/c/b3722fb69468693555f531cddda5c30444726dac
- https://git.kernel.org/stable/c/f1e197a665c2148ebc25fe09c53689e60afea195
- https://git.kernel.org/stable/c/f251ccef1d864790e5253386e95544420b7cd8f3