Executive brief
A vulnerability was identified in the Linux kernel's GTP (GPRS Tunneling Protocol) driver, which is used for mobile data networking. The issue occurs when network namespaces—isolated virtual networks within the system—are deleted, but certain networking components are not properly cleaned up. This can lead to a system crash or instability (kernel panic), potentially allowing a local user to disrupt the availability of the server or device.
Technical details
A resource management vulnerability exists in the Linux kernel GTP driver (drivers/net/gtp.c). The function gtp_newlink() incorrectly links a new GTP device to the network namespace of the device itself (dev_net) rather than the source network namespace (src_net) where the UDP tunnel socket resides. Consequently, when the source namespace is deleted, the GTP device remains active, causing a reference counting 'splat' and potential kernel instability during namespace cleanup. The fix ensures the device is linked to the socket's namespace and adds an iteration in gtp_net_exit_batch_rtnl() to properly remove all GTP devices during namespace destruction. This is a local vulnerability requiring the ability to manipulate network namespaces.
Affected products
- Linux Linux Kernel All versions prior to fixed stable releases (e.g., 6.13-rc5)
Timeline
- 2025-01-10: patched: Initial patch authored
- 2025-01-31: advisory: CVE published
References
- https://git.kernel.org/stable/c/036f8d814a2cd11ee8ef62b8f3e7ce5dec0ee4f3
- https://git.kernel.org/stable/c/5f1678346109ff3a6d229d33437fcba3cce9209d
- https://git.kernel.org/stable/c/86f73d4ab2f27deeff22ba9336ad103d94f12ac7
- https://git.kernel.org/stable/c/bb11f992f5a475bc68ef959f17a55306f0328495
- https://git.kernel.org/stable/c/c986380c1d5274c4d5e935addc807d6791cc23eb
- https://git.kernel.org/stable/c/eb28fd76c0a08a47b470677c6cef9dd1c60e92d1
- https://git.kernel.org/stable/c/efec287cbac92ac6ee8312a89221854760e13b34