Executive brief
A vulnerability exists in the Linux kernel's Open vSwitch component, which is used to manage virtual network switching. A local attacker could exploit this flaw to cause a system crash or potentially execute unauthorized code by triggering a 'use-after-free' error during network port operations. This could lead to a full compromise of the affected system's availability and data integrity.
Technical details
A use-after-free (UAF) vulnerability exists in the Open vSwitch implementation within the Linux kernel. The function 'ovs_vport_cmd_fill_info()' could be invoked without proper RTNL (Routing Netlink) or RCU (Read-Copy-Update) protection when accessing network namespace information. This lack of synchronization allows a local attacker to trigger a race condition where network structures are accessed after being freed. An attacker can exploit this to achieve arbitrary code execution or cause a kernel panic. The issue has been resolved by implementing RCU protection and using 'dev_net_rcu()' to safely access the network namespace.
Affected products
- Linux Linux Kernel 4.15 to 5.4.291, 5.5 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.79, 6.7 to 6.12.16, 6.13 to 6.13.4
Timeline
- 2025-02-07: other: Patch authored
- 2025-02-26: disclosed: CVE published by kernel.org
- 2025-02-27: advisory: NVD publication date
References
- https://git.kernel.org/stable/c/5828937742af74666192835d657095d95c53dbd0
- https://git.kernel.org/stable/c/7e01abc34e87abd091e619161a20f54ed4e3e2da
- https://git.kernel.org/stable/c/8ec57509c36c8b9a23e50b7858dda0c520a2d074
- https://git.kernel.org/stable/c/90b2f49a502fa71090d9f4fe29a2f51fe5dff76d
- https://git.kernel.org/stable/c/a849a10de5e04d798f7f286a2f1ca174719a617a
- https://git.kernel.org/stable/c/a8816b3f1f151373fd30f1996f00480126c8bb11
- https://git.kernel.org/stable/c/a884f57600e463f69d7b279c4598b865260b62a1