Executive brief
A vulnerability was identified in the Linux kernel's networking subsystem, specifically within the Netfilter flowtable component used for high-speed packet processing. A technical error in how the system handles hardware offload tasks could allow a local user to cause a system crash or instability. This affects the availability of the system but does not directly expose private data.
Technical details
A vulnerability exists in 'net/netfilter/nf_flow_table_offload.c' within the Linux kernel due to an uninitialized variable. Specifically, the 'extack' (extended ACK) structure in the 'nf_flow_offload_tuple' function was used without being zero-initialized. This can lead to the kernel processing garbage data from the stack when hardware offload fails or reports status, potentially resulting in a kernel panic or denial of service. The issue is reachable by a local user with sufficient privileges to configure network flow tables. Patches have been released across multiple stable kernel branches (5.10.y, 5.15.y, 6.1.y, 6.6.y, and 6.10.y).
Affected products
- Linux Linux Kernel 5.5 to 5.10.224, 5.11 to 5.15.165, 5.16 to 6.1.106, 6.2 to 6.6.47, 6.7 to 6.10.6
Timeline
- 2024-08-06: other: Patch authored
- 2024-09-11: advisory: CVE published
References
- https://git.kernel.org/stable/c/119be227bc04f5035efa64cb823b8a5ca5e2d1c1
- https://git.kernel.org/stable/c/356beb911b63a8cff34cb57f755c2a2d2ee9dec7
- https://git.kernel.org/stable/c/7eafeec6be68ebd6140a830ce9ae68ad5b67ec78
- https://git.kernel.org/stable/c/c7b760499f7791352b49b11667ed04b23d7f5b0f
- https://git.kernel.org/stable/c/e5ceff2196dc633c995afb080f6f44a72cff6e1d
- https://git.kernel.org/stable/c/e9767137308daf906496613fd879808a07f006a2
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html