In the Linux kernel, the following vulnerability has been resolved:
net: do not delay dst_entries_add() in dst_release()
dst_entries_add() uses per-cpu data that might be freed at netns
dismantle from ip6_route_net_exit() calling dst_entries_destroy()
Before ip6_route_net_exit() can be called, we release all
the dsts associated with this netns, via calls to dst_release(),
which waits an rcu grace period before calling dst_destroy()
dst_entries_add() use in dst_destroy() is racy, because
dst_entries_destroy() could have been called already.
Decrementing the number of dsts must happen sooner.
Notes:
1) in CONFIG_XFRM case, dst_destroy() can call
dst_release_immediate(child), this might also cause UAF
if the child does not have DST_NOCOUNT set.
IPSEC maintainers might take a look and see how to address this.
2) There is also discussion about removing this count of dst,
which might happen in future kernels.
References
Configurations
Configuration 1 (hide)
|
History
17 Nov 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Nov 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Nov 2024, 18:34
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
25 Oct 2024, 15:41
Type | Values Removed | Values Added |
---|---|---|
First Time |
Linux linux Kernel
Linux |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.0 |
References | () https://git.kernel.org/stable/c/3c7c918ec0aa3555372c5a57f18780b7a96c5cfc - Patch | |
References | () https://git.kernel.org/stable/c/ac888d58869bb99753e7652be19a151df9ecb35d - Patch | |
References | () https://git.kernel.org/stable/c/eae7435b48ffc8e9be0ff9cfeae40af479a609dd - Patch | |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:* cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:* |
23 Oct 2024, 15:12
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
21 Oct 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-21 20:15
Updated : 2024-11-17 15:15
NVD link : CVE-2024-50036
Mitre link : CVE-2024-50036
CVE.ORG link : CVE-2024-50036
JSON object : View
Products Affected
linux
- linux_kernel
CWE