Junglewise Threat Intelligence

CVE-2024-49944: Linux Kernel null pointer dereference in SCTP socket listening

CVE-2024-49944 · Severity: medium · CVSS 5.5 · Published 2024-10-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system fails to properly reset a network socket's state after a specific connection setup step fails. This can lead to a system-wide denial of service (crash) if the same network operation is attempted again.

Technical details

A null pointer dereference exists in the SCTP implementation within the Linux kernel. In `sctp_listen_start()`, if `sctp_autobind()` fails, the socket state (`sk_state`) is not correctly reset to `CLOSED`. If a subsequent call to `sctp_inet_listen()` is made while `SCTP_REUSE_PORT` is set, the kernel attempts to dereference `bind_hash` while the state is incorrectly set to `LISTENING`. Because `bind_hash` is NULL in this state, it triggers a kernel panic. This can be exploited by a local user with sufficient privileges to create and manipulate SCTP sockets. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 2.6.30 to 5.10.227, 5.11 to 5.15.168, 5.16 to 6.1.113, 6.2 to 6.6.55, 6.7 to 6.10.14, 6.11 to 6.11.3

Timeline

  • 2024-10-21: advisory: Initial public disclosure and NVD publication
  • 2024-10-03: patched: Mainline kernel patch committed

References

Related threats