Junglewise Threat Intelligence

CVE-2024-46743: Linux Kernel out-of-bounds read in of_irq_parse_raw

CVE-2024-46743 · Severity: high · CVSS 7.1 · Published 2024-09-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's device management system could allow a local user to trigger an out-of-bounds memory read. This occurs when the system processes hardware interrupt information for certain devices. An exploit could lead to a system crash or the exposure of sensitive kernel memory, potentially impacting system stability and data confidentiality.

Technical details

An out-of-bounds read vulnerability exists in the Linux kernel's Device Tree (OF) interrupt parsing logic. Specifically, in `of_irq_parse_raw()`, if a device address is smaller than the interrupt parent node's `#address-cells` property, the kernel may read past the allocated buffer for the device address. This was identified via KASAN (Kernel Address Sanitizer) during interrupt map walks. A local attacker with the ability to trigger device tree parsing (e.g., via overlays or specific hardware interactions) could exploit this to read sensitive kernel memory or cause a denial of service (system crash). The fix involves copying the device address into a sufficiently sized buffer before processing.

Affected products

  • Linux Linux Kernel up to (excluding) 4.19.322, 4.20 to (excluding) 5.4.284, 5.5 to (excluding) 5.10.226, 5.11 to (excluding) 5.15.167, 5.16 to (excluding) 6.1.110, 6.2 to (excluding) 6.6.51, 6.7 to (excluding) 6.10.10, 6.11-rc1

Timeline

  • 2024-08-12: other: Patch authored
  • 2024-09-12: patched: Patch committed to stable tree
  • 2024-09-18: disclosed: CVE published

References

Related threats