Executive brief
A vulnerability exists in the Linux kernel's SCSI Generic (sg) driver, which manages communication between applications and SCSI devices. A flaw in how the system closes device handles could allow a local attacker to cause a system crash or potentially execute unauthorized code. This issue primarily impacts system stability and could be used to escalate privileges on a compromised machine.
Technical details
A use-after-free (UAF) vulnerability was identified in the Linux kernel SCSI Generic (sg) driver within the sg_release() function. The root cause is a race condition where kref_put() is called to decrement a reference count before a mutex (open_rel_lock) is released. If the reference count reaches zero, the cleanup function sg_remove_sfp() is triggered, freeing the 'sfp' structure while the code still attempts to access it or its associated 'sdp' structure during the subsequent mutex unlock operation. A local attacker with access to SCSI generic devices could exploit this to cause a kernel panic or achieve arbitrary code execution. The fix involves reordering the operations to ensure kref_put() is called only after the mutex is unlocked.
Affected products
- Linux Linux Kernel 3.16.85 to 6.6.66, 6.7 to 6.12.5, 6.13-rc1
Timeline
- 2024-11-20: other: Patch submitted by developer
- 2024-12-27: disclosed: CVE published
- 2024-12-14: patched: Initial fix merged into stable branches
References
- https://git.kernel.org/stable/c/198b89dd5a595ee3f96e5ce5c448b0484cd0e53c
- https://git.kernel.org/stable/c/1f5e2f1ca5875728fcf62bc1a054707444ab4960
- https://git.kernel.org/stable/c/275b8347e21ab8193e93223a8394a806e4ba8918
- https://git.kernel.org/stable/c/285ce1f89f8d414e7eecab5ef5118cd512596318
- https://git.kernel.org/stable/c/59b30afa578637169e2819536bb66459fdddc39d
- https://git.kernel.org/stable/c/e19acb1926c4a1f30ee1ec84d8afba2d975bd534
- https://git.kernel.org/stable/c/f10593ad9bc36921f623361c9e3dd96bd52d85ee