Junglewise Threat Intelligence

CVE-2024-46745: Linux Kernel resource exhaustion in uinput ABS_MT_SLOT validation

CVE-2024-46745 · Severity: medium · CVSS 5.5 · Published 2024-09-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's user-level input (uinput) subsystem could allow a local user to strain system resources. By requesting an extremely large number of input 'slots' (such as those used for multi-touch tracking), an attacker can trigger memory allocation failures and force the system to perform intensive memory reclamation. This can lead to system instability or a denial-of-service condition.

Technical details

A resource exhaustion vulnerability (CWE-770) exists in the Linux kernel's uinput driver. The `uinput_validate_absinfo` function did not previously enforce a maximum limit on the number of multi-touch (MT) slots requested via the `ABS_MT_SLOT` code. A local attacker can exploit this by requesting an 'unreasonable' number of slots, which triggers a memory allocation failure in `input_mt_init_slots()`. While the kernel handles the allocation failure itself, the process of attempting to fulfill the massive request puts undue burden on the system's memory management subsystem, potentially leading to a denial-of-service. The fix introduces a hard limit of 100 slots to ensure allocations remain within reasonable bounds (less than two pages).

Affected products

  • Linux Linux Kernel up to 4.19.322, 4.20 to 5.4.284, 5.5 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.110, 6.2 to 6.6.51, 6.7 to 6.10.10, 6.11-rc1 to 6.11-rc4

Timeline

  • 2024-08-04: patched: Initial patch authored by Dmitry Torokhov
  • 2024-09-18: disclosed: CVE published

References

Related threats