Junglewise Threat Intelligence

CVE-2024-56631: Linux Kernel use-after-free in SCSI Generic driver sg_release

CVE-2024-56631 · Severity: high · CVSS 7.8 · Published 2024-12-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's SCSI Generic (sg) driver, which manages communication between applications and SCSI devices. A flaw in how the system closes device handles could allow a local attacker to cause a system crash or potentially execute unauthorized code. This issue primarily impacts system stability and could be used to escalate privileges on a compromised machine.

Technical details

A use-after-free (UAF) vulnerability was identified in the Linux kernel SCSI Generic (sg) driver within the sg_release() function. The root cause is a race condition where kref_put() is called to decrement a reference count before a mutex (open_rel_lock) is released. If the reference count reaches zero, the cleanup function sg_remove_sfp() is triggered, freeing the 'sfp' structure while the code still attempts to access it or its associated 'sdp' structure during the subsequent mutex unlock operation. A local attacker with access to SCSI generic devices could exploit this to cause a kernel panic or achieve arbitrary code execution. The fix involves reordering the operations to ensure kref_put() is called only after the mutex is unlocked.

Affected products

  • Linux Linux Kernel 3.16.85 to 6.6.66, 6.7 to 6.12.5, 6.13-rc1

Timeline

  • 2024-11-20: other: Patch submitted by developer
  • 2024-12-27: disclosed: CVE published
  • 2024-12-14: patched: Initial fix merged into stable branches

References

Related threats