Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system processes specific types of network traffic (VLAN packets) using a 'peek' operation, which allows an application to look at data without removing it from the queue. An exploit could lead to a kernel panic, resulting in a complete system shutdown and denial of service.
Technical details
A race condition and improper buffer handling exist in the af_packet component of the Linux kernel. Specifically, the vlan_get_tci() function incorrectly modified the socket buffer (skb) during MSG_PEEK operations. Because MSG_PEEK allows multiple threads or CPUs to access the same skb simultaneously, this modification led to a 'skb_under_panic' kernel bug (invalid opcode) when concurrent access occurred. The fix reworks vlan_get_tci() to treat the skb as constant and avoids direct modification of the buffer pointers. This vulnerability is reachable by local users with the ability to create or interact with AF_PACKET sockets.
Affected products
- Linux Linux Kernel 4.19.320 to 4.20, 5.4.282 to 5.4.289, 5.10.224 to 5.10.233, 5.15.165 to 5.15.176, 6.1.103 to 6.1.124, 6.6.44 to 6.6.70, 6.10.3 to 6.12.9, 6.13-rc1 to 6.13-rc5
Timeline
- 2024-12-30: patched: Initial patch submitted by Eric Dumazet
- 2025-01-15: advisory: CVE-2024-57902 published
References
- https://git.kernel.org/stable/c/65c67049e9ed481f6b52264b39618b8c6dfb1d3e
- https://git.kernel.org/stable/c/66ffb0cf2125dcf9e902eede4a43653a24fd9cb2
- https://git.kernel.org/stable/c/77ee7a6d16b6ec07b5c3ae2b6b60a24c1afbed09
- https://git.kernel.org/stable/c/7aa78d0d8546d8ce5a764add3f55d72e707c18f1
- https://git.kernel.org/stable/c/b65292a548d847099a4fe0fff53122a06e798e25
- https://git.kernel.org/stable/c/d91b4a9baa018a001d5c884e236c0cfd31f9f4a1
- https://git.kernel.org/stable/c/fa57f07ba0622c8692f40e1300adca59277b0044