Executive brief
A vulnerability was identified in the Linux kernel's networking component responsible for managing IP tunnels. Under certain conditions, the system may access internal networking data without proper synchronization, which can lead to system instability or a kernel crash. This could allow a local user with basic access to disrupt the availability of the system.
Technical details
A 'suspicious RCU usage' vulnerability exists in the Linux kernel's IPv4 ip_tunnel implementation. The function ip_tunnel_init_flow() was found to traverse RCU-protected lists via l3mdev_master_upper_ifindex_by_index_rcu() without holding the RCU read lock in certain code paths (e.g., during tunnel creation via rtnetlink). This violation of the RCU synchronization primitive can lead to use-after-free conditions or kernel panics. The fix involves migrating to l3mdev_master_upper_ifindex_by_index(), which internally handles the acquisition of the RCU read lock. The vulnerability is reachable by local users via netlink messages.
Affected products
- Linux Linux Kernel 5.10.227 to 5.10.229, 5.15.168 to 5.15.171, 5.18 to 6.1.116, 6.2 to 6.6.60, 6.7 to 6.11.7, 6.12-rc1 to 6.12-rc5
Timeline
- 2024-11-19: advisory: Initial disclosure and patch release
References
- https://git.kernel.org/stable/c/5edcb3fdb12c3d46a6e79eeeec27d925b80fc168
- https://git.kernel.org/stable/c/699b48fc31727792edf2cab3829586ae6ba649e2
- https://git.kernel.org/stable/c/6dfaa458fe923211c766238a224e0a3c0522935c
- https://git.kernel.org/stable/c/72c0f482e39c87317ebf67661e28c8d86c93e870
- https://git.kernel.org/stable/c/ad4a3ca6a8e886f6491910a3ae5d53595e40597d
- https://git.kernel.org/stable/c/e2742758c9c85c84e077ede5f916479f724e11c2
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html