Junglewise Threat Intelligence

CVE-2024-43882: Linux Kernel privilege escalation via ToCToU in execve

CVE-2024-43882 · Severity: high · CVSS 7 · Published 2024-08-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's program execution logic could allow a local user to gain unauthorized administrative (root) privileges. This occurs due to a timing issue where the system checks a file's permissions but then uses different, updated security settings when actually running the program. In practice, an attacker could exploit this during system updates or software installations to bypass security restrictions and take full control of the system.

Technical details

A Time-of-Check to Time-of-Use (ToCToU) vulnerability exists in the Linux kernel's exec implementation (fs/exec.c). When a file is opened for execution via do_filp_open(), the kernel performs initial permission checks; however, the actual application of set-uid/set-gid bits occurs later in the bprm_fill_uid() path. If the file's metadata (mode, UID, or GID) is modified between these two points—for example, by a concurrent chmod operation during a package update—a user might successfully initiate execution of a file they shouldn't be able to run as root. The fix involves re-validating execute permissions under the inode lock within bprm_fill_uid() to ensure metadata hasn't changed since the initial check. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel up to 4.19.320, 4.20 to 5.4.282, 5.5 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.106, 6.2 to 6.6.47, 6.7 to 6.10.6

Timeline

  • 2024-08-08: patched: Initial patch authored by Kees Cook
  • 2024-08-21: advisory: CVE-2024-43882 published

References

Related threats