Junglewise Threat Intelligence

CVE-2024-46865: Linux Kernel uninitialized resource in fou_core.c

CVE-2024-46865 · Severity: high · CVSS 7.1 · Published 2024-09-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking component responsible for Foo-over-UDP (FOU) encapsulation. This flaw could allow a local attacker to cause a system crash or potentially access sensitive information from the system's memory. The issue has been resolved in recent kernel updates, and administrators are advised to apply the latest security patches for their Linux distributions.

Technical details

A 'Use of Uninitialized Resource' (CWE-908) vulnerability exists in net/ipv4/fou.c (or fou_core.c in some versions) within the gue_gro_receive function. The root cause is a logic error where a 'goto out' statement is executed if the 'fou' pointer is NULL before the 'grc' (Generic Receive Offload remote checksum) structure is initialized. Consequently, the uninitialized 'grc' structure is used in subsequent operations. A local attacker can exploit this to trigger a kernel panic (DoS) or potentially leak kernel memory contents. Patches have been released across multiple stable kernel branches (5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.10.y).

Affected products

  • Linux Linux Kernel 5.10.226, 5.15.167, 6.1.110, 6.6.51, 6.10.10

Timeline

  • 2024-09-27: advisory: NVD publication date
  • 2024-09-09: patched: Initial fix committed to mainline kernel

References

Related threats