cbcvebase.
CVE-2024-26923
published 2024-04-25

CVE-2024-26923: In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix garbage collector racing against connect() Garbage collector does not take…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.21%
10.8th percentile
In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix garbage collector racing against connect() Garbage collector does not take into account the risk of embryo getting enqueued during the garbage collection. If such embryo has a peer that carries SCM_RIGHTS, two consecutive passes of scan_children() may see a different set of children. Leading to an incorrectly elevated inflight count, and then a dangling pointer within the gc_inflight_list. sockets are AF_UNIX/SOCK_STREAM S is an unconnected socket L is a listening in-flight socket bound to addr, not in fdtable V's fd will be passed via sendmsg(), gets inflight count bumped connect(S, addr) sendmsg(S, [V]); close(V) __unix_gc() ---------------- ------------------------- ----------- NS = unix_create1() skb1 = sock_wmalloc(NS) L = unix_find_other(addr) unix_state_lock(L) unix_peer(S) = NS // V count=1 inflight=0 NS = unix_peer(S) skb2 = sock_alloc() skb_queue_tail(NS, skb2[V]) // V became in-flight // V count=2 inflight=1 close(V) // V count=1 inflight=1 // GC candidate condition met for u in gc_inflight_list: if (total_refs == inflight_refs) add u to gc_candidates // gc_candidates={L, V} for u in gc_candidates: scan_children(u, dec_inflight) // embryo (skb1) was not // reachable from L yet, so V's // inflight remains unchanged __skb_queue_tail(L, skb1) unix_state_unlock(L) for u in gc_candidates: if (u.inflight) scan_children(u, inc_inflight_move_tail) // V count=1 inflight=2 (!) If there is a GC-candidate listening socket, lock/unlock its state. This makes GC wait until the end of any ongoing connect() to that socket. After flipping the lock, a possibly SCM-laden embryo is already enqueued. And if there is another embryo coming, it can not possibly carry SCM_RIGHTS. At this point, unix_inflight() can not happen because unix_gc_lock is already taken. Inflight graph remains unaffected.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
googleandroid
linuxlinux
linuxlinux>= 1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 < a36ae0ec2353015f0f6762e59f4c2dbc0c906423a36ae0ec2353015f0f6762e59f4c2dbc0c906423
linuxlinux>= 1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 < 343c5372d5e17b306db5f8f3c895539b06e3177f343c5372d5e17b306db5f8f3c895539b06e3177f
linuxlinux>= 1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 < 2e2a03787f4f0abc0072350654ab0ef3324d9db32e2a03787f4f0abc0072350654ab0ef3324d9db3
linuxlinux>= 1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 < e76c2678228f6aec74b305ae30c9374cc2f28a51e76c2678228f6aec74b305ae30c9374cc2f28a51
linuxlinux>= 1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 < b75722be422c276b699200de90527d01c602ea7cb75722be422c276b699200de90527d01c602ea7c
linuxlinux>= 1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 < 507cc232ffe53a352847893f8177d276c3b532a9507cc232ffe53a352847893f8177d276c3b532a9
linuxlinux>= 1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 < dbdf7bec5c920200077d693193f989cb1513f009dbdf7bec5c920200077d693193f989cb1513f009
linuxlinux>= 1fd05ba5a2f2aa8e7b9b52ef55df850e2e7d54c9 < 47d8ac011fe1c9251070e1bd64cb10b48193ec5147d8ac011fe1c9251070e1bd64cb10b48193ec51
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-189.2095.4.0-189.209
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
linuxlinux_kernel>= 0 < 4.4.0-257.2914.4.0-257.291
linuxlinux_kernel>= 0 < 4.15.0-232.2444.15.0-232.244

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.