cbcvebase.
CVE-2024-40983
published 2024-07-12

CVE-2024-40983: In the Linux kernel, the following vulnerability has been resolved: tipc: force a dst refcount before doing decryption As it says in commit 3bc07321ccc2…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.5th percentile
In the Linux kernel, the following vulnerability has been resolved: tipc: force a dst refcount before doing decryption As it says in commit 3bc07321ccc2 ("xfrm: Force a dst refcount before entering the xfrm type handlers"): "Crypto requests might return asynchronous. In this case we leave the rcu protected region, so force a refcount on the skb's destination entry before we enter the xfrm type input/output handlers." On TIPC decryption path it has the same problem, and skb_dst_force() should be called before doing decryption to avoid a possible crash. Shuang reported this issue when this warning is triggered: [] WARNING: include/net/dst.h:337 tipc_sk_rcv+0x1055/0x1ea0 [tipc] [] Kdump: loaded Tainted: G W --------- - - 4.18.0-496.el8.x86_64+debug [] Workqueue: crypto cryptd_queue_worker [] RIP: 0010:tipc_sk_rcv+0x1055/0x1ea0 [tipc] [] Call Trace: [] tipc_sk_mcast_rcv+0x548/0xea0 [tipc] [] tipc_rcv+0xcf5/0x1060 [tipc] [] tipc_aead_decrypt_done+0x215/0x2e0 [tipc] [] cryptd_aead_crypt+0xdb/0x190 [] cryptd_queue_worker+0xed/0x190 [] process_one_work+0x93d/0x17e0

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 < 3eb1b39627892c4e26cb0162b75725aa5fcc60c83eb1b39627892c4e26cb0162b75725aa5fcc60c8
linuxlinux>= fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 < 692803b39a36e63ac73208e0a3769ae6a2f9bc76692803b39a36e63ac73208e0a3769ae6a2f9bc76
linuxlinux>= fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 < 623c90d86a61e3780f682b32928af469c66ec4c2623c90d86a61e3780f682b32928af469c66ec4c2
linuxlinux>= fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 < b57a4a2dc8746cea58a922ebe31b6aa629d69d93b57a4a2dc8746cea58a922ebe31b6aa629d69d93
linuxlinux>= fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 < 6808b41371670c51feea14f63ade211e781009306808b41371670c51feea14f63ade211e78100930
linuxlinux>= fc1b6d6de2208774efd2a20bf0daddb02d18b1e0 < 2ebe8f840c7450ecbfca9d18ac92e9ce9155e2692ebe8f840c7450ecbfca9d18ac92e9ce9155e269
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.11 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.966.1.96
linuxlinux_kernel>= 5.5 < 5.10.2215.10.221
linuxlinux_kernel>= 6.2 < 6.6.366.6.36
linuxlinux_kernel>= 6.7 < 6.9.76.9.7

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.