Junglewise Threat Intelligence

CVE-2024-44990: Linux Kernel NULL pointer dereference in bonding driver IPsec offload

CVE-2024-44990 · Severity: medium · CVSS 5.5 · Published 2024-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's network bonding driver could allow a local user to crash the system. The issue occurs when the system attempts to process encrypted network traffic (IPsec) on a bonded network interface that does not have an active backup connection. This results in a system crash (kernel panic), leading to a denial of service.

Technical details

A NULL pointer dereference vulnerability exists in the 'bond_ipsec_offload_ok' function within 'drivers/net/bonding/bond_main.c' of the Linux kernel. The issue stems from a failure to validate the existence of an active slave interface ('curr_active_slave') before dereferencing it during IPsec hardware encryption offload checks. A local attacker could potentially trigger this condition to cause a kernel panic and denial of service. The vulnerability has been addressed by adding a check for the active slave pointer before it is accessed. Patches are available for various stable kernel branches including 5.10, 5.15, 6.1, 6.6, and 6.10.

Affected products

  • Linux Linux Kernel 5.9 to 5.10.225, 5.11 to 5.15.166, 5.16 to 6.1.107, 6.2 to 6.6.48, 6.7 to 6.10.7, 6.11-rc1 to 6.11-rc4

Timeline

  • 2024-08-16: patched: Initial patch authored
  • 2024-09-04: advisory: NVD publication date

References

Related threats