cbcvebase.
CVE-2024-35955
published 2024-05-20

CVE-2024-35955: In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix possible use-after-free issue on kprobe registration When unloading a module…

PriorityP347high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.17%
63.8th percentile
In the Linux kernel, the following vulnerability has been resolved: kprobes: Fix possible use-after-free issue on kprobe registration When unloading a module, its state is changing MODULE_STATE_LIVE -> MODULE_STATE_GOING -> MODULE_STATE_UNFORMED. Each change will take a time. `is_module_text_address()` and `__module_text_address()` works with MODULE_STATE_LIVE and MODULE_STATE_GOING. If we use `is_module_text_address()` and `__module_text_address()` separately, there is a chance that the first one is succeeded but the next one is failed because module->state becomes MODULE_STATE_UNFORMED between those operations. In `check_kprobe_address_safe()`, if the second `__module_text_address()` is failed, that is ignored because it expected a kernel_text address. But it may have failed simply because module->state has been changed to MODULE_STATE_UNFORMED. In this case, arm_kprobe() will try to modify non-exist module text address (use-after-free). To fix this problem, we should not use separated `is_module_text_address()` and `__module_text_address()`, but use only `__module_text_address()` once and do `try_module_get(module)` which is only available with MODULE_STATE_LIVE.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 1c836bad43f3e2ff71cc397a6e6ccb4e7bd116f8 < b5808d40093403334d939e2c3c417144d12a6f33b5808d40093403334d939e2c3c417144d12a6f33
linuxlinux>= 28f6c37a2910f565b4f5960df52b2eccae28c891 < 62029bc9ff2c17a4e3a2478d83418ec57541380862029bc9ff2c17a4e3a2478d83418ec575413808
linuxlinux>= 28f6c37a2910f565b4f5960df52b2eccae28c891 < d15023fb407337028a654237d8968fefdcf87c2fd15023fb407337028a654237d8968fefdcf87c2f
linuxlinux>= 28f6c37a2910f565b4f5960df52b2eccae28c891 < 36b57c7d2f8b7de224980f1a284432846ad71ca036b57c7d2f8b7de224980f1a284432846ad71ca0
linuxlinux>= 28f6c37a2910f565b4f5960df52b2eccae28c891 < 325f3fb551f8cd672dbbfc4cf58b14f9ee3fc9e8325f3fb551f8cd672dbbfc4cf58b14f9ee3fc9e8
linuxlinux>= 2a49b025c36ae749cee7ccc4b7e456e02539cdc3 < 5062d1f4f07facbdade0f402d9a04a788f52e26d5062d1f4f07facbdade0f402d9a04a788f52e26d
linuxlinux>= 4.14.291 < 4.154.15
linuxlinux>= 4.19.256 < 4.19.3134.19.313
linuxlinux>= 5.10.137 < 5.10.2165.10.216
linuxlinux>= 5.15.61 < 5.15.1575.15.157
linuxlinux>= 5.18.18 < 5.195.19
linuxlinux>= 5.19.2 < 5.205.20
linuxlinux>= 5.4.211 < 5.4.2755.4.275
linuxlinux>= 6a119c1a584aa7a2c6216458f1f272bf1bc93a93 < 93eb31e7c3399e326259f2caa17be1e821f5a41293eb31e7c3399e326259f2caa17be1e821f5a412
linuxlinux>= a1edb85e60fdab1e14db63ae8af8db3f0d798fb6 < 2df2dd27066cdba8041e46a64362325626bdfb2e2df2dd27066cdba8041e46a64362325626bdfb2e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.