Junglewise Threat Intelligence

CVE-2024-50142: Linux Kernel validation bypass in XFRM subsystem

CVE-2024-50142 · Severity: medium · CVSS 5.5 · Published 2024-11-07

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's IPsec (XFRM) subsystem, which manages secure network communications. A local attacker could exploit this flaw to cause a system crash or instability by providing specially crafted network security parameters. This issue primarily impacts system availability and could lead to a denial-of-service condition.

Technical details

A vulnerability in net/xfrm/xfrm_user.c arises because verify_newsa_info fails to properly validate address prefix lengths when the selector family (sel.family) is set to AF_UNSPEC while the Security Association (SA) family is set to a specific protocol like AF_INET. This mismatch allows a local attacker to bypass prefix length limits during SA creation. When the state is later copied, the selector family is updated to the SA family, but the previously unvalidated (and potentially out-of-bounds) prefix length remains. This can lead to kernel memory corruption or crashes. The fix ensures that the SA family is used for validation if the selector family is unset.

Affected products

  • Linux Linux Kernel 2.6.12 up to 4.19.323, 4.20 up to 5.4.285, 5.5 up to 5.10.229, 5.11 up to 5.15.170, 5.16 up to 6.1.115, 6.2 up to 6.6.59, 6.7 up to 6.11.6

Timeline

  • 2024-10-01: disclosed: Initial patch authored
  • 2024-11-07: advisory: CVE-2024-50142 published

References

Related threats