Executive brief
A vulnerability in the Linux kernel's network bonding driver could allow a local user to cause a system crash. The issue occurs when the system handles encrypted network traffic (IPsec) while reconfiguring network interfaces. This can lead to a 'blue screen' style failure (kernel oops), resulting in a complete service outage for the affected machine.
Technical details
A NULL pointer dereference exists in the Linux kernel bonding driver (drivers/net/bonding/bond_main.c) within the XFRM offload path. The vulnerability is caused by setting 'real_dev' to NULL in 'bond_ipsec_del_sa_all' while packets may still be in transit or while 'xdo_dev_offload_ok()' is being called in parallel. Because subsequent callbacks assume 'real_dev' is valid, this race condition triggers a kernel panic (page fault). The issue affects systems using hardware encryption offload with bonded interfaces. Patches have been released for various stable kernel branches including 5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.10.y.
Affected products
- Linux Linux Kernel 5.9 to 5.10.225, 5.11 to 5.15.166, 5.16 to 6.1.107, 6.2 to 6.6.48, 6.7 to 6.10.7
Timeline
- 2024-08-16: patched: Initial fix authored by Nikolay Aleksandrov
- 2024-09-04: advisory: NVD advisory published
References
- https://git.kernel.org/stable/c/21816b696c172c19d53a30d45ee005cce246ed21
- https://git.kernel.org/stable/c/2f72c6a66bcd7e0187ec085237fee5db27145294
- https://git.kernel.org/stable/c/4582d4ff413a07d4ed8a4823c652dc5207760548
- https://git.kernel.org/stable/c/7fa9243391ad2afe798ef4ea2e2851947b95754f
- https://git.kernel.org/stable/c/89fc1dca79db5c3e7a2d589ecbf8a3661c65f436
- https://git.kernel.org/stable/c/f8cde9805981c50d0c029063dc7d82821806fc44
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html