Junglewise Threat Intelligence

CVE-2024-57902: Linux Kernel kernel panic in af_packet vlan_get_tci

CVE-2024-57902 · Severity: medium · CVSS 5.5 · Published 2025-01-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system processes specific types of network traffic (VLAN packets) using a 'peek' operation, which allows an application to look at data without removing it from the queue. An exploit could lead to a kernel panic, resulting in a complete system shutdown and denial of service.

Technical details

A race condition and improper buffer handling exist in the af_packet component of the Linux kernel. Specifically, the vlan_get_tci() function incorrectly modified the socket buffer (skb) during MSG_PEEK operations. Because MSG_PEEK allows multiple threads or CPUs to access the same skb simultaneously, this modification led to a 'skb_under_panic' kernel bug (invalid opcode) when concurrent access occurred. The fix reworks vlan_get_tci() to treat the skb as constant and avoids direct modification of the buffer pointers. This vulnerability is reachable by local users with the ability to create or interact with AF_PACKET sockets.

Affected products

  • Linux Linux Kernel 4.19.320 to 4.20, 5.4.282 to 5.4.289, 5.10.224 to 5.10.233, 5.15.165 to 5.15.176, 6.1.103 to 6.1.124, 6.6.44 to 6.6.70, 6.10.3 to 6.12.9, 6.13-rc1 to 6.13-rc5

Timeline

  • 2024-12-30: patched: Initial patch submitted by Eric Dumazet
  • 2025-01-15: advisory: CVE-2024-57902 published

References

Related threats