Junglewise Threat Intelligence

CVE-2024-56672: Linux Kernel use-after-free in blkcg_unpin_online

CVE-2024-56672 · Severity: high · CVSS 7 · Published 2024-12-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's block control group (blk-cgroup) subsystem, which manages disk I/O resources. Under specific conditions, the system may attempt to access memory that has already been freed during the removal of resource limits. This could lead to a system crash or allow a local user to potentially gain unauthorized elevated privileges, although the flaw is difficult to trigger in real-world scenarios.

Technical details

A use-after-free (UAF) vulnerability exists in the blkcg_unpin_online() function within the block/blk-cgroup.c component of the Linux kernel. The issue stems from the function attempting to access a parent blkcg pointer using blkcg_parent(blkcg) after the current blkcg has been destroyed by blkcg_destroy_blkgs(blkcg), which can trigger the freeing of the object. While the race condition is difficult to hit due to RCU grace periods and workqueue indirection, it is reachable by local users with sufficient permissions to manipulate cgroups. The fix involves caching the parent pointer before the destruction of the child object. Patches have been backported to multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 5.7 to 6.1.121, 6.2 to 6.6.67, 6.7 to 6.12.6, 6.13-rc1, 6.13-rc2

Timeline

  • 2024-12-06: patched: Initial patch authored by Tejun Heo
  • 2024-12-27: disclosed: CVE-2024-56672 assigned and published

References

Related threats