Junglewise Threat Intelligence

CVE-2024-40980: Linux Kernel improper locking in drop_monitor

CVE-2024-40980 · Severity: medium · CVSS 5.5 · Published 2024-07-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's network drop monitor component could allow a local user to cause a system crash or instability. This issue specifically affects systems running Real-Time (RT) kernel configurations, where certain internal locking mechanisms behave differently. An exploit could lead to a denial-of-service, impacting the availability of the affected server or device.

Technical details

A locking issue exists in the Linux kernel's drop_monitor component, specifically within the trace_drop_common() function. In Real-Time (RT) kernel configurations, standard spin_locks are converted into sleeping locks. Because trace_drop_common() is called with preemption disabled (atomic context), acquiring a sleeping spin_lock triggers a 'sleeping function called from invalid context' error (kernel splat). This vulnerability is categorized under CWE-667 (Improper Locking). An attacker with local access could potentially trigger this condition to cause a denial-of-service. The fix involves replacing the standard spin_lock with a raw_spin_lock to ensure the lock does not sleep, maintaining compatibility with RT kernel requirements.

Affected products

  • Linux Linux Kernel up to 5.4.279, 5.5 to 5.10.221, 5.11 to 5.15.162, 5.16 to 6.1.96, 6.2 to 6.6.36

Timeline

  • 2024-07-12: advisory: NVD publication date
  • 2024-06-27: patched: Fix committed to stable kernel tree

References

Related threats