cbcvebase.
CVE-2024-36927
published 2024-05-30

CVE-2024-36927: In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.17%
6.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ipv4: Fix uninit-value access in __ip_make_skb() KMSAN reported uninit-value access in __ip_make_skb() [1]. __ip_make_skb() tests HDRINCL to know if the skb has icmphdr. However, HDRINCL can cause a race condition. If calling setsockopt(2) with IP_HDRINCL changes HDRINCL while __ip_make_skb() is running, the function will access icmphdr in the skb even if it is not included. This causes the issue reported by KMSAN. Check FLOWI_FLAG_KNOWN_NH on fl4->flowi4_flags instead of testing HDRINCL on the socket. Also, fl4->fl4_icmp_type and fl4->fl4_icmp_code are not initialized. These are union in struct flowi4 and are implicitly initialized by flowi4_init_output(), but we should not rely on specific union layout. Initialize these explicitly in raw_sendmsg(). [1] BUG: KMSAN: uninit-value in __ip_make_skb+0x2b74/0x2d20 net/ipv4/ip_output.c:1481 __ip_make_skb+0x2b74/0x2d20 net/ipv4/ip_output.c:1481 ip_finish_skb include/net/ip.h:243 [inline] ip_push_pending_frames+0x4c/0x5c0 net/ipv4/ip_output.c:1508 raw_sendmsg+0x2381/0x2690 net/ipv4/raw.c:654 inet_sendmsg+0x27b/0x2a0 net/ipv4/af_inet.c:851 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x274/0x3c0 net/socket.c:745 __sys_sendto+0x62c/0x7b0 net/socket.c:2191 __do_sys_sendto net/socket.c:2203 [inline] __se_sys_sendto net/socket.c:2199 [inline] __x64_sys_sendto+0x130/0x200 net/socket.c:2199 do_syscall_64+0xd8/0x1f0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x6d/0x75 Uninit was created at: slab_post_alloc_hook mm/slub.c:3804 [inline] slab_alloc_node mm/slub.c:3845 [inline] kmem_cache_alloc_node+0x5f6/0xc50 mm/slub.c:3888 kmalloc_reserve+0x13c/0x4a0 net/core/skbuff.c:577 __alloc_skb+0x35a/0x7c0 net/core/skbuff.c:668 alloc_skb include/linux/skbuff.h:1318 [inline] __ip_append_data+0x49ab/0x68c0 net/ipv4/ip_output.c:1128 ip_append_data+0x1e7/0x260 net/ipv4/ip_output.c:1365 raw_sendmsg+0x22b1/0x2690 net/ipv4/raw.c:648 inet_sendmsg+0

Affected

44 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.315 < 4.154.15
linuxlinux>= 4.19.283 < 4.204.20
linuxlinux>= 5.10.180 < 5.10.2485.10.248
linuxlinux>= 5.15.111 < 5.15.1985.15.198
linuxlinux>= 5.4.243 < 5.55.5
linuxlinux>= 566785731c6dd41ef815196ddc36d1ae30a63763 < 88c66f1879f322f11de34d37b2d3d87497afdcb688c66f1879f322f11de34d37b2d3d87497afdcb6
linuxlinux>= 6.1.28 < 6.1.1406.1.140
linuxlinux>= 6.2.15 < 6.36.3
linuxlinux>= 6.3.2 < 6.46.4
linuxlinux>= 99e5acae193e369b71217efe6f1dad42f3f18815 < 5db08343ddb1b239320612036c398e4e1bb528185db08343ddb1b239320612036c398e4e1bb52818
linuxlinux>= 99e5acae193e369b71217efe6f1dad42f3f18815 < f5c603ad4e6fcf42f84053e882ebe20184bb309ef5c603ad4e6fcf42f84053e882ebe20184bb309e
linuxlinux>= 99e5acae193e369b71217efe6f1dad42f3f18815 < fc1092f51567277509563800a3c56732070b6aa4fc1092f51567277509563800a3c56732070b6aa4
linuxlinux>= a54ec573d9b81b05d368f8e6edc1b3e49f688658 < 20d3eb00ab81462d554ac6d09691b8d9aa5a574120d3eb00ab81462d554ac6d09691b8d9aa5a5741
linuxlinux>= fc60067260c20da8cddcf968bec47416f3e2cde2 < 55bf541e018b76b3750cb6c6ea18c46e1ac5562e55bf541e018b76b3750cb6c6ea18c46e1ac5562e
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.