cbcvebase.
CVE-2024-46782
published 2024-09-18

CVE-2024-46782: In the Linux kernel, the following vulnerability has been resolved: ila: call nf_unregister_net_hooks() sooner syzbot found an use-after-free Read in…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
14.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ila: call nf_unregister_net_hooks() sooner syzbot found an use-after-free Read in ila_nf_input [1] Issue here is that ila_xlat_exit_net() frees the rhashtable, then call nf_unregister_net_hooks(). It should be done in the reverse way, with a synchronize_rcu(). This is a good match for a pre_exit() method. [1] BUG: KASAN: use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline] BUG: KASAN: use-after-free in __rhashtable_lookup include/linux/rhashtable.h:604 [inline] BUG: KASAN: use-after-free in rhashtable_lookup include/linux/rhashtable.h:646 [inline] BUG: KASAN: use-after-free in rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672 Read of size 4 at addr ffff888064620008 by task ksoftirqd/0/16 CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.11.0-rc4-syzkaller-00238-g2ad6d23f465a #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024 Call Trace: __dump_stack lib/dump_stack.c:93 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119 print_address_description mm/kasan/report.c:377 [inline] print_report+0x169/0x550 mm/kasan/report.c:488 kasan_report+0x143/0x180 mm/kasan/report.c:601 rht_key_hashfn include/linux/rhashtable.h:159 [inline] __rhashtable_lookup include/linux/rhashtable.h:604 [inline] rhashtable_lookup include/linux/rhashtable.h:646 [inline] rhashtable_lookup_fast+0x77a/0x9b0 include/linux/rhashtable.h:672 ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:132 [inline] ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline] ila_nf_input+0x1fe/0x3c0 net/ipv6/ila/ila_xlat.c:190 nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline] nf_hook_slow+0xc3/0x220 net/netfilter/core.c:626 nf_hook include/linux/netfilter.h:269 [inline] NF_HOOK+0x29e/0x450 include/linux/netfilter.h:312 __netif_receive_skb_one_core net/core/dev.c:5661 [inline] __netif_receive_skb+0x1ea/0x650 net/core/dev.c:5775 process_backlog+0x662/0x15b0 net/co

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 43d34110882b97ba1ec66cc8234b18983efb9abf43d34110882b97ba1ec66cc8234b18983efb9abf
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < dcaf4e2216824839d26727a15b638c6a677bd9fcdcaf4e2216824839d26727a15b638c6a677bd9fc
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 93ee345ba349922834e6a9d1dadabaedcc12dce693ee345ba349922834e6a9d1dadabaedcc12dce6
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < bda4d84ac0d5421b346faee720011f58bdb99673bda4d84ac0d5421b346faee720011f58bdb99673
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 925c18a7cff93d8a4320d652351294ff7d0ac93c925c18a7cff93d8a4320d652351294ff7d0ac93c
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 18a5a16940464b301ea91bf5da3a324aedb347b218a5a16940464b301ea91bf5da3a324aedb347b2
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 47abd8adddbc0aecb8f231269ef659148d5dabe447abd8adddbc0aecb8f231269ef659148d5dabe4
linuxlinux>= 7f00feaf107645d95a6d87e99b4d141ac0a08efd < 031ae72825cef43e4650140b800ad58bf7a6a466031ae72825cef43e4650140b800ad58bf7a6a466
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.226-15.10.226-1
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 6.10.11-16.10.11-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-125.1355.15.0-125.135
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 4.20 < 5.4.2845.4.284
linuxlinux_kernel>= 4.5 < 4.19.3224.19.322
linuxlinux_kernel>= 5.11 < 5.15.1675.15.167
linuxlinux_kernel>= 5.16 < 6.1.1106.1.110
linuxlinux_kernel>= 5.5 < 5.10.2265.10.226
linuxlinux_kernel>= 6.2 < 6.6.516.6.51

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.