Junglewise Threat Intelligence

CVE-2024-44987: Linux Kernel use-after-free in ip6_send_skb

CVE-2024-44987 · Severity: high · CVSS 7.8 · Published 2024-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's IPv6 networking component, which manages how the system communicates over modern internet protocols. An attacker with local access to the system could exploit this flaw to cause a system crash or potentially gain unauthorized access to sensitive information. This issue affects the stability and security of servers and workstations running impacted versions of the Linux operating system.

Technical details

A use-after-free (UAF) vulnerability exists in the ip6_send_skb() function within the Linux kernel's IPv6 stack. The issue arises because the routing table (rt) pointer can be dereferenced after ip6_local_out() has returned, at which point the memory may have already been freed. This occurs because the code fails to properly hold the RCU read lock during certain socket operations. A local attacker can trigger this race condition via crafted raw IPv6 socket messages, potentially leading to a kernel crash (DoS) or arbitrary code execution. Patches have been released across multiple stable kernel branches to ensure proper RCU locking.

Affected products

  • Linux Linux Kernel 6.11-rc3 and earlier versions

Timeline

  • 2024-08-20: patched: Initial fix authored by Eric Dumazet
  • 2024-09-04: advisory: CVE-2024-44987 published

References

Related threats