CVE-2024-36972

Source
https://cve.org/CVERecord?id=CVE-2024-36972
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36972.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-36972
Aliases
Downstream
Related
Published
2024-06-10T14:57:42.271Z
Modified
2026-03-14T12:34:17.532608Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
af_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock.
Details

In the Linux kernel, the following vulnerability has been resolved:

afunix: Update unixsk(sk)->oobskb under skreceive_queue lock.

Billy Jheng Bing-Jhong reported a race between __unixgc() and queueoob().

__unixgc() tries to garbage-collect close()d inflight sockets, and then if the socket has MSGOOB in unixsk(sk)->oobskb, GC will drop the reference and set NULL to it locklessly.

However, the peer socket still can send MSGOOB message and queueoob() can update unixsk(sk)->oobskb concurrently, leading NULL pointer dereference. [0]

To fix the issue, let's update unixsk(sk)->oobskb under the skreceivequeue's lock and take it everywhere we touch oob_skb.

Note that we defer kfreeskb() in manageoob() to silence lockdep false-positive (See [1]).

PF: supervisor write access in kernel mode PF: errorcode(0x0002) - not-present page PGD 8000000009f5e067 P4D 8000000009f5e067 PUD 9f5d067 PMD 0 Oops: 0002 [#1] PREEMPT SMP PTI CPU: 3 PID: 50 Comm: kworker/3:1 Not tainted 6.9.0-rc5-00191-gd091e579b864 #110 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 Workqueue: events delayedfput RIP: 0010:skbdequeue (./include/linux/skbuff.h:2386 ./include/linux/skbuff.h:2402 net/core/skbuff.c:3847) Code: 39 e3 74 3e 8b 43 10 48 89 ef 83 e8 01 89 43 10 49 8b 44 24 08 49 c7 44 24 08 00 00 00 00 49 8b 14 24 49 c7 04 24 00 00 00 00 <48> 89 42 08 48 89 10 e8 e7 c5 42 00 4c 89 e0 5b 5d 41 5c c3 cc cc RSP: 0018:ffffc900001bfd48 EFLAGS: 00000002 RAX: 0000000000000000 RBX: ffff8880088f5ae8 RCX: 00000000361289f9 RDX: 0000000000000000 RSI: 0000000000000206 RDI: ffff8880088f5b00 RBP: ffff8880088f5b00 R08: 0000000000080000 R09: 0000000000000001 R10: 0000000000000003 R11: 0000000000000001 R12: ffff8880056b6a00 R13: ffff8880088f5280 R14: 0000000000000001 R15: ffff8880088f5a80 FS: 0000000000000000(0000) GS:ffff88807dd80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000008 CR3: 0000000006314000 CR4: 00000000007506f0 PKRU: 55555554 Call Trace: <TASK> unixreleasesock (net/unix/afunix.c:654) unixrelease (net/unix/afunix.c:1050) __sockrelease (net/socket.c:660) sockclose (net/socket.c:1423) __fput (fs/filetable.c:423) delayedfput (fs/filetable.c:444 (discriminator 3)) processonework (kernel/workqueue.c:3259) workerthread (kernel/workqueue.c:3329 kernel/workqueue.c:3416) kthread (kernel/kthread.c:388) retfromfork (arch/x86/kernel/process.c:153) retfromforkasm (arch/x86/entry/entry64.S:257) </TASK> Modules linked in: CR2: 0000000000000008

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36972.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4fe505c63aa3273135a57597fda761e9aecc7668
Fixed
518a994aa0b87d96f1bc6678a7035df5d1fcd7a1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e0e09186d8821ad59806115d347ea32efa43ca4b
Fixed
4bf6964451c3cb411fbaa1ae8b214b3d97a59bf1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b74aa9ce13d02b7fd37c5325b99854f91b9b4276
Fixed
d59ae9314b97e01c76a4171472441e55721ba636
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1279f9d9dec2d7462823a18c29ad61359e0a007d
Fixed
4708f49add84a57ce0ccc7bf9a6269845c631cc3
Fixed
9841991a446c87f90f66f4b9fee6fe934c1336a2
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
82ae47c5c3a6b27fdc0f9e83c1499cb439c56140

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36972.json"