Junglewise Threat Intelligence

CVE-2024-45018: Linux Kernel uninitialized variable in Netfilter flowtable offload

CVE-2024-45018 · Severity: medium · CVSS 5.5 · Published 2024-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem, specifically within the Netfilter flowtable component used for high-speed packet processing. A technical error in how the system handles hardware offload tasks could allow a local user to cause a system crash or instability. This affects the availability of the system but does not directly expose private data.

Technical details

A vulnerability exists in 'net/netfilter/nf_flow_table_offload.c' within the Linux kernel due to an uninitialized variable. Specifically, the 'extack' (extended ACK) structure in the 'nf_flow_offload_tuple' function was used without being zero-initialized. This can lead to the kernel processing garbage data from the stack when hardware offload fails or reports status, potentially resulting in a kernel panic or denial of service. The issue is reachable by a local user with sufficient privileges to configure network flow tables. Patches have been released across multiple stable kernel branches (5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.10.y).

Affected products

  • Linux Linux Kernel 5.5 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.106, 6.2 to 6.6.47, 6.7 to 6.10.6

Timeline

  • 2024-08-06: other: Patch authored
  • 2024-09-11: advisory: CVE published

References

Related threats