Executive brief
A vulnerability in the Linux kernel's network bonding driver could allow a local user to crash the system. The issue occurs when the system attempts to process encrypted network traffic (IPsec) on a bonded network interface that does not have an active backup connection. This results in a system crash (kernel panic), leading to a denial of service.
Technical details
A NULL pointer dereference vulnerability exists in the 'bond_ipsec_offload_ok' function within 'drivers/net/bonding/bond_main.c' of the Linux kernel. The issue stems from a failure to validate the existence of an active slave interface ('curr_active_slave') before dereferencing it during IPsec hardware encryption offload checks. A local attacker could potentially trigger this condition to cause a kernel panic and denial of service. The vulnerability has been addressed by adding a check for the active slave pointer before it is accessed. Patches are available for various stable kernel branches including 5.10, 5.15, 6.1, 6.6, and 6.10.
Affected products
- Linux Linux Kernel 5.9 to 5.10.225, 5.11 to 5.15.166, 5.16 to 6.1.107, 6.2 to 6.6.48, 6.7 to 6.10.7, 6.11-rc1 to 6.11-rc4
Timeline
- 2024-08-16: patched: Initial patch authored
- 2024-09-04: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/0707260a18312bbcd2a5668584e3692d0a29e3f6
- https://git.kernel.org/stable/c/2f5bdd68c1ce64bda6bef4d361a3de23b04ccd59
- https://git.kernel.org/stable/c/32a0173600c63aadaf2103bf02f074982e8602ab
- https://git.kernel.org/stable/c/81216b9352be43f8958092d379f6dec85443c309
- https://git.kernel.org/stable/c/95c90e4ad89d493a7a14fa200082e466e2548f9d
- https://git.kernel.org/stable/c/b70b0ddfed31fc92c8dc722d0afafc8e14cb550c
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html