cbcvebase.
CVE-2024-35976
published 2024-05-20

CVE-2024-35976: In the Linux kernel, the following vulnerability has been resolved: xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING syzbot reported an illegal…

PriorityP431medium6.7CVSS 3.1
AVLACHPRNUINSUCHIHAN
EPSS
0.26%
17.1th percentile
In the Linux kernel, the following vulnerability has been resolved: xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING syzbot reported an illegal copy in xsk_setsockopt() [1] Make sure to validate setsockopt() @optlen parameter. [1] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in xsk_setsockopt+0x909/0xa40 net/xdp/xsk.c:1420 Read of size 4 at addr ffff888028c6cde3 by task syz-executor.0/7549 CPU: 0 PID: 7549 Comm: syz-executor.0 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0x169/0x550 mm/kasan/report.c:488 kasan_report+0x143/0x180 mm/kasan/report.c:601 copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] copy_from_sockptr include/linux/sockptr.h:55 [inline] xsk_setsockopt+0x909/0xa40 net/xdp/xsk.c:1420 do_sock_setsockopt+0x3af/0x720 net/socket.c:2311 __sys_setsockopt+0x1ae/0x250 net/socket.c:2334 __do_sys_setsockopt net/socket.c:2343 [inline] __se_sys_setsockopt net/socket.c:2340 [inline] __x64_sys_setsockopt+0xb5/0xd0 net/socket.c:2340 do_syscall_64+0xfb/0x240 entry_SYSCALL_64_after_hwframe+0x6d/0x75 RIP: 0033:0x7fb40587de69 Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 e1 20 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007fb40665a0c8 EFLAGS: 00000246 ORIG_RAX: 0000000000000036 RAX: ffffffffffffffda RBX: 00007fb4059abf80 RCX: 00007fb40587de69 RDX: 0000000000000005 RSI: 000000000000011b RDI: 0000000000000006 RBP: 00007fb4058ca47a R08: 0000000000000002 R09: 0000000000000000 R10: 0000000020001980 R11: 00000

Affected

25 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.90-1 (bookworm)linux 6.1.90-1 (bookworm)
linuxlinux
linuxlinux>= 423f38329d267969130fb6f2c685f73d72687558 < beb99266830520e15fbc6ca8cc5a5240d76851fdbeb99266830520e15fbc6ca8cc5a5240d76851fd
linuxlinux>= 423f38329d267969130fb6f2c685f73d72687558 < 0b45c25d60e38f5c2cb6823f886773a34323306d0b45c25d60e38f5c2cb6823f886773a34323306d
linuxlinux>= 423f38329d267969130fb6f2c685f73d72687558 < a82984b3c6a7e8c7937dba6e857ddf829d149417a82984b3c6a7e8c7937dba6e857ddf829d149417
linuxlinux>= 423f38329d267969130fb6f2c685f73d72687558 < f0a068de65d5b7358e9aff792716afa9333f3922f0a068de65d5b7358e9aff792716afa9333f3922
linuxlinux>= 423f38329d267969130fb6f2c685f73d72687558 < 2a523f14a3f53b46ff0e1fafd215b0bc5f6783aa2a523f14a3f53b46ff0e1fafd215b0bc5f6783aa
linuxlinux>= 423f38329d267969130fb6f2c685f73d72687558 < b143e19dc28c3211f050f7848d87d9b0a170e10cb143e19dc28c3211f050f7848d87d9b0a170e10c
linuxlinux>= 423f38329d267969130fb6f2c685f73d72687558 < 2eb979fbb2479bcd7e049f2f9978b6590dd8a0e62eb979fbb2479bcd7e049f2f9978b6590dd8a0e6
linuxlinux>= 423f38329d267969130fb6f2c685f73d72687558 < 237f3cf13b20db183d3706d997eedc3c49eacd44237f3cf13b20db183d3706d997eedc3c49eacd44
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.90-16.1.90-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 6.8.9-16.8.9-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-116.1265.15.0-116.126
linuxlinux_kernel>= 0 < 6.8.0-38.386.8.0-38.38
linuxlinux_kernel>= 4.18 < 4.19.3174.19.317
linuxlinux_kernel>= 4.20 < 5.4.2785.4.278
linuxlinux_kernel>= 5.11 < 5.15.1565.15.156
linuxlinux_kernel>= 5.16 < 6.1.876.1.87
linuxlinux_kernel>= 5.5 < 5.10.2165.10.216
linuxlinux_kernel>= 6.2 < 6.6.286.6.28
linuxlinux_kernel>= 6.7 < 6.8.76.8.7

CVSS provenance

nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.7MEDIUM
vendor_redhat6.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.