Executive brief
A vulnerability in the Linux kernel's networking subsystem could allow a local user to crash the system. The issue exists in the Netfilter component, which is responsible for filtering and processing network traffic. By sending specifically crafted network data, an attacker can trigger a system halt (kernel panic), leading to a complete denial of service.
Technical details
A vulnerability in 'net/netfilter/nft_payload.c' in the Linux kernel arises from insufficient validation of offset and length parameters before calling 'skb_checksum()'. When 'nft_payload_set_eval' processes a packet, if the requested offset plus length exceeds the actual skbuff (skb) length, 'skb_checksum()' triggers a 'BUG_ON(len)' during its internal iteration. This results in a kernel panic and immediate system crash. The issue affects systems using nftables with packet mangling support. Patches have been released across multiple stable kernel branches to sanitize these inputs before the checksum calculation is performed.
Affected products
- Linux Linux Kernel 4.5 to 4.19.323, 4.20 to 5.4.285, 5.5 to 5.10.229, 5.11 to 5.15.171, 5.16 to 6.1.116, 6.2 to 6.6.60, 6.7 to 6.11.7, 6.12-rc1 to 6.12-rc5
Timeline
- 2024-11-09: disclosed
- 2024-11-09: advisory
- 2024-11-08: patched: Patched in various stable branches including 6.11.7, 6.6.60, 6.1.116, etc.
References
- https://git.kernel.org/stable/c/0ab3be58b45b996764aba0187b46de19b3e58a72
- https://git.kernel.org/stable/c/a661ed364ae6ae88c2fafa9ddc27df1af2a73701
- https://git.kernel.org/stable/c/ac7df3fc80fc82bcc3b1e8f6ebc0d2c435d0c534
- https://git.kernel.org/stable/c/b1d2de8a669fa14c499a385e056944d5352b3b40
- https://git.kernel.org/stable/c/c43e0ea848e7b9bef7a682cbc5608022d6d29d7b
- https://git.kernel.org/stable/c/d3217323525f7596427124359e76ea0d8fcc9874
- https://git.kernel.org/stable/c/d5953d680f7e96208c29ce4139a0e38de87a57fe