cbcvebase.
CVE-2024-42109
published 2024-07-30

CVE-2024-42109: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally flush pending work before notifier syzbot reports…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.3th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: unconditionally flush pending work before notifier syzbot reports: KASAN: slab-uaf in nft_ctx_update include/net/netfilter/nf_tables.h:1831 KASAN: slab-uaf in nft_commit_release net/netfilter/nf_tables_api.c:9530 KASAN: slab-uaf int nf_tables_trans_destroy_work+0x152b/0x1750 net/netfilter/nf_tables_api.c:9597 Read of size 2 at addr ffff88802b0051c4 by task kworker/1:1/45 [..] Workqueue: events nf_tables_trans_destroy_work Call Trace: nft_ctx_update include/net/netfilter/nf_tables.h:1831 [inline] nft_commit_release net/netfilter/nf_tables_api.c:9530 [inline] nf_tables_trans_destroy_work+0x152b/0x1750 net/netfilter/nf_tables_api.c:9597 Problem is that the notifier does a conditional flush, but its possible that the table-to-be-removed is still referenced by transactions being processed by the worker, so we need to flush unconditionally. We could make the flush_work depend on whether we found a table to delete in nf-next to avoid the flush for most cases. AFAICS this problem is only exposed in nf-next, with commit e169285f8c56 ("netfilter: nf_tables: do not store nft_ctx in transaction objects"), with this commit applied there is an unconditional fetch of table->family which is whats triggering the above splat.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
debianlinux-6.1< linux 6.1.98-1 (bookworm)linux 6.1.98-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 2c9f0293280e258606e54ed2b96fa71498432eae < 55a40406aac555defe9bdd0adec9508116ce7cb155a40406aac555defe9bdd0adec9508116ce7cb1
linuxlinux>= 2c9f0293280e258606e54ed2b96fa71498432eae < 09e650c3a3a7d804430260510534ccbf71c75b2e09e650c3a3a7d804430260510534ccbf71c75b2e
linuxlinux>= 2c9f0293280e258606e54ed2b96fa71498432eae < 9f6958ba2e902f9820c594869bd710ba74b7c4c09f6958ba2e902f9820c594869bd710ba74b7c4c0
linuxlinux>= 41841b585e53babdfb0fa6fdfa54f6d7c28c1206 < 4c06c13317b9a08decedcd7aaf706691e336277c4c06c13317b9a08decedcd7aaf706691e336277c
linuxlinux>= 5.15.129 < 5.15.1635.15.163
linuxlinux>= 6.1.50 < 6.1.986.1.98
linuxlinux>= 6.4.13 < 6.56.5
linuxlinux>= f22954f8c58fd5f5489f5980796914e306757e77 < 3325628cb36b7f216c5716e7b5124d9dc81199e43325628cb36b7f216c5716e7b5124d9dc81199e4
linuxlinux_kernel>= 0 < 6.1.98-16.1.98-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 6.9.9-16.9.9-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-48.486.8.0-48.48
linuxlinux_kernel>= 5.15.129 < 5.15.1635.15.163
linuxlinux_kernel>= 6.1.50 < 6.1.986.1.98
linuxlinux_kernel>= 6.5 < 6.6.396.6.39
linuxlinux_kernel>= 6.7 < 6.9.96.9.9

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.