Junglewise Threat Intelligence

CVE-2024-50033: Linux Kernel SLIP use of uninitialized memory in slhc_remember

CVE-2024-50033 · Severity: high · CVSS 7.1 · Published 2024-10-21

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's SLIP (Serial Line IP) driver could allow a local attacker to cause a system crash or potentially access sensitive information from the computer's memory. The issue occurs because the system does not properly validate the size of incoming network packets before processing them. This affects systems using older serial-based networking protocols or PPP connections.

Technical details

A use of uninitialized resource vulnerability (CWE-908) exists in the slhc_remember() function within drivers/net/slip/slhc.c. The function previously only checked if a packet was at least 20 bytes, which is insufficient to guarantee the presence of both IPv4 and TCP headers. An attacker can provide a specially crafted 'runt' packet that bypasses these checks, causing the kernel to read uninitialized data from the stack or heap during header compression/decompression. This can lead to a kernel information leak or a denial-of-service (system crash). The fix introduces robust bounds checking to ensure the packet buffer actually contains the expected IPv4 and TCP header lengths defined in the packet fields.

Affected products

  • Linux Linux Kernel 3.2 to 5.10.226, 5.11 to 5.15.167, 5.16 to 6.1.112, 6.2 to 6.6.56, 6.7 to 6.11.3

Timeline

  • 2024-10-09: patched: Initial patch submitted by Eric Dumazet
  • 2024-10-21: advisory: CVE-2024-50033 published

References

Related threats