Executive brief
A vulnerability in the Linux kernel's DPAA Ethernet driver could allow a local user to view small amounts of sensitive system memory. When the system sends very small network packets (under 60 bytes), it may inadvertently include up to three bytes of unrelated data from the computer's memory in the packet sent over the network. This could lead to the disclosure of information that should otherwise be protected.
Technical details
A memory leak vulnerability exists in the Data Path Acceleration Architecture (DPAA) Ethernet driver (`drivers/net/ethernet/freescale/dpaa/dpaa_eth.c`) within the Linux kernel. The issue arises because packet data is read as 32-bit words; when transmitting packets smaller than the minimum Ethernet frame length (ETH_ZLEN, 60 bytes), the driver may leak up to three bytes of the buffer following the actual data. An attacker with local access could trigger this by sending small packets (e.g., `ping -s 11`) and capturing the resulting network traffic to inspect the leaked padding bytes. The vulnerability has been resolved by ensuring all packets are padded to ETH_ZLEN using `__skb_put_padto` before transmission.
Affected products
- Linux Linux Kernel 4.10 to 6.1.111, 6.2 to 6.6.52, 6.7 to 6.10.11, 6.11-rc1 to 6.11-rc7
Timeline
- 2024-09-27: disclosed
- 2024-09-27: advisory
- 2024-09-11: patched: Mainline kernel patch applied
References
- https://git.kernel.org/stable/c/1f31f51bfc8214a6deaac2920e6342cb9d019133
- https://git.kernel.org/stable/c/34fcac26216ce17886af3eb392355b459367af1a
- https://git.kernel.org/stable/c/38f5db5587c0ee53546b28c50ba128253181ac83
- https://git.kernel.org/stable/c/cbd7ec083413c6a2e0c326d49e24ec7d12c7a9e0
- https://git.kernel.org/stable/c/cd5b9d657ecd44ad5f254c3fea3a6ab1cf0e2ef7
- https://git.kernel.org/stable/c/ce8eabc912fe9b9a62be1a5c6af5ad2196e90fc2
- https://git.kernel.org/stable/c/dc43a096cfe65b5c32168313846c5cd135d08f1d