Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system fails to properly reset a network socket's state after a specific connection setup step fails. This can lead to a system-wide denial of service (crash) if the same network operation is attempted again.
Technical details
A null pointer dereference exists in the SCTP implementation within the Linux kernel. In `sctp_listen_start()`, if `sctp_autobind()` fails, the socket state (`sk_state`) is not correctly reset to `CLOSED`. If a subsequent call to `sctp_inet_listen()` is made while `SCTP_REUSE_PORT` is set, the kernel attempts to dereference `bind_hash` while the state is incorrectly set to `LISTENING`. Because `bind_hash` is NULL in this state, it triggers a kernel panic. This can be exploited by a local user with sufficient privileges to create and manipulate SCTP sockets. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 2.6.30 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.55, 6.7 to 6.10.14, 6.11 to 6.11.3
Timeline
- 2024-10-21: advisory: Initial public disclosure and NVD publication
- 2024-10-03: patched: Mainline kernel patch committed
References
- https://git.kernel.org/stable/c/0e4e2e60556c6ed00e8450b720f106a268d23062
- https://git.kernel.org/stable/c/7f64cb5b4d8c872296eda0fdce3bcf099eec7aa7
- https://git.kernel.org/stable/c/89bbead9d897c77d0b566349c8643030ff2abeba
- https://git.kernel.org/stable/c/8beee4d8dee76b67c75dc91fd8185d91e845c160
- https://git.kernel.org/stable/c/9230a59eda0878d7ecaa901d876aec76f57bd455
- https://git.kernel.org/stable/c/dd70c8a89ef99c3d53127fe19e51ef47c3f860fa
- https://git.kernel.org/stable/c/e7a8442195e8ebd97df467ce4742980ab57edcce