Junglewise Threat Intelligence

CVE-2024-42070: Linux Kernel nf_tables information leak in register store validation

CVE-2024-42070 · Severity: medium · CVSS 5.5 · Published 2024-07-29

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking subsystem could allow a local user to cause a system crash or potentially leak sensitive internal memory information. The issue exists in the nf_tables component, which is used for managing network firewall rules. While primarily impacting system stability, such flaws can sometimes be used by attackers to bypass security protections.

Technical details

A vulnerability in nf_tables exists due to conditional register store validation for NFT_DATA_VALUE. The root cause is that the validation logic did not account for all possible datatypes (NFT_DATA_VALUE or NFT_DATA_VERDICT) when inferring register types. A local attacker can exploit this to leak pointers to internal chain objects through the registers or cause a denial of service. The fix introduces a helper function to correctly infer and validate the register type from the set datatype, ensuring proper bounds and type checking. Patching is available across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel up to 3.13, 3.14 to 4.19.317, 4.20 to 5.4.279, 5.5 to 5.10.221, 5.11 to 5.15.162, 5.16 to 6.1.97, 6.2 to 6.6.37, 6.7 to 6.9.8

Timeline

  • 2024-06-26: patched: Initial patch authored by Pablo Neira Ayuso
  • 2024-07-29: disclosed: CVE published to NVD

References

Related threats