Junglewise Threat Intelligence

CVE-2024-45016: Linux Kernel use-after-free in netem_enqueue

CVE-2024-45016 · Severity: medium · CVSS 5.5 · Published 2024-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's network emulation component could allow a local user to cause a system crash or instability. The issue stems from how the system handles duplicated network packets, which can lead to memory corruption. This could result in a denial-of-service, impacting the availability of the affected system.

Technical details

A use-after-free vulnerability exists in netem_enqueue() within the Linux kernel's traffic control subsystem. The bug was introduced by incorrect return value handling when packets are duplicated; the function would return NET_XMIT_SUCCESS even if the enqueue failed. This causes the parent queuing discipline (qdisc) to incorrectly increment its packet length counter (qlen). During qdisc destruction, the mismatch causes the kernel to skip necessary cleanup (qlen_notify), resulting in dangling pointers in classful qdiscs like DRR. A local attacker can exploit this to trigger a use-after-free condition, leading to a kernel panic. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 5.0 to 5.4.283, 5.5 to 5.10.225, 5.11 to 5.15.166, 5.16 to 6.1.107, 6.2 to 6.6.48, 6.7 to 6.10.7

Timeline

  • 2024-09-11: advisory: Initial disclosure and NVD publication
  • 2024-08-29: patched: Fixes merged into various stable kernel branches

References

Related threats