Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash. The issue occurs when the system tries to read network device settings while the device is being reset or removed. This results in a 'race condition' that triggers a kernel panic, leading to a complete system outage or denial of service.
Technical details
A race condition exists in the ethtool component of the Linux kernel when retrieving link settings. Specifically, the __ethtool_get_link_ksettings() function lacked a check to verify if a network device was still present. A local attacker or a sysfs reader can trigger this race by attempting to read device state (e.g., via duplex_show or speed_show in sysfs) while the device is undergoing a reset or removal. This leads to a null pointer dereference or invalid memory access (kernel panic). The fix involves moving the netif_device_present() check into the ethtool core to protect all callers.
Affected products
- Linux Linux Kernel 2.6.33 to 5.4.283, 5.5 to 5.10.225, 5.11 to 5.15.166, 5.16 to 6.1.108, 6.2 to 6.6.49, 6.7 to 6.10.8
Timeline
- 2024-08-23: other: Patch authored
- 2024-09-04: patched: Patch committed to stable branches
- 2024-09-13: disclosed: CVE published
References
- https://git.kernel.org/stable/c/1d6d9b5b1b95bfeccb84386a51b7e6c510ec13b2
- https://git.kernel.org/stable/c/7a8d98b6d6484d3ad358510366022da080c37cbc
- https://git.kernel.org/stable/c/842a40c7273ba1c1cb30dda50405b328de1d860e
- https://git.kernel.org/stable/c/94ab317024ba373d37340893d1c0358638935fbb
- https://git.kernel.org/stable/c/9bba5955eed160102114d4cc00c3d399be9bdae4
- https://git.kernel.org/stable/c/a699781c79ecf6cfe67fb00a0331b4088c7c8466
- https://git.kernel.org/stable/c/ec7b4f7f644018ac293cb1b02528a40a32917e62