cbcvebase.
CVE-2024-56658
published 2024-12-27

CVE-2024-56658: In the Linux kernel, the following vulnerability has been resolved: net: defer final 'struct net' free in netns dismantle Ilya reported a slab-use-after-free…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: defer final 'struct net' free in netns dismantle Ilya reported a slab-use-after-free in dst_destroy [1] Issue is in xfrm6_net_init() and xfrm4_net_init() : They copy xfrm[46]_dst_ops_template into net->xfrm.xfrm[46]_dst_ops. But net structure might be freed before all the dst callbacks are called. So when dst_destroy() calls later : if (dst->ops->destroy) dst->ops->destroy(dst); dst->ops points to the old net->xfrm.xfrm[46]_dst_ops, which has been freed. See a relevant issue fixed in : ac888d58869b ("net: do not delay dst_entries_add() in dst_release()") A fix is to queue the 'struct net' to be freed after one another cleanup_net() round (and existing rcu_barrier()) [1] BUG: KASAN: slab-use-after-free in dst_destroy (net/core/dst.c:112) Read of size 8 at addr ffff8882137ccab0 by task swapper/37/0 Dec 03 05:46:18 kernel: CPU: 37 UID: 0 PID: 0 Comm: swapper/37 Kdump: loaded Not tainted 6.12.0 #67 Hardware name: Red Hat KVM/RHEL, BIOS 1.16.1-1.el9 04/01/2014 Call Trace: dump_stack_lvl (lib/dump_stack.c:124) print_address_description.constprop.0 (mm/kasan/report.c:378) ? dst_destroy (net/core/dst.c:112) print_report (mm/kasan/report.c:489) ? dst_destroy (net/core/dst.c:112) ? kasan_addr_to_slab (mm/kasan/common.c:37) kasan_report (mm/kasan/report.c:603) ? dst_destroy (net/core/dst.c:112) ? rcu_do_batch (kernel/rcu/tree.c:2567) dst_destroy (net/core/dst.c:112) rcu_do_batch (kernel/rcu/tree.c:2567) ? __pfx_rcu_do_batch (kernel/rcu/tree.c:2491) ? lockdep_hardirqs_on_prepare (kernel/locking/lockdep.c:4339 kernel/locking/lockdep.c:4406) rcu_core (kernel/rcu/tree.c:2825) handle_softirqs (kernel/softirq.c:554) __irq_exit_rcu (kernel/softirq.c:589 kernel/softirq.c:428 kernel/softirq.c:637) irq_exit_rcu (kernel/softirq.c:651) sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1049 arch/x86/kernel/apic/apic.c:1049) asm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702) R

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.12.54 < 3.133.13
linuxlinux>= 3.18.27 < 3.193.19
linuxlinux>= 4.1.17 < 4.24.2
linuxlinux>= 4.3.5 < 4.44.4
linuxlinux>= a8a572a6b5f2a79280d6e302cb3c1cb1fbaeb3e8 < c261dcd61c9e88a8f1a66654354d32295a975230c261dcd61c9e88a8f1a66654354d32295a975230
linuxlinux>= a8a572a6b5f2a79280d6e302cb3c1cb1fbaeb3e8 < dac465986a4a38cd2f13e934f562b6ca344e5720dac465986a4a38cd2f13e934f562b6ca344e5720
linuxlinux>= a8a572a6b5f2a79280d6e302cb3c1cb1fbaeb3e8 < 3267b254dc0a04dfa362a2be24573cfa6d2d78f53267b254dc0a04dfa362a2be24573cfa6d2d78f5
linuxlinux>= a8a572a6b5f2a79280d6e302cb3c1cb1fbaeb3e8 < b7a79e51297f7b82adb687086f5cb2da446f1e40b7a79e51297f7b82adb687086f5cb2da446f1e40
linuxlinux>= a8a572a6b5f2a79280d6e302cb3c1cb1fbaeb3e8 < 6610c7f8a8d47fd1123eed55ba8c11c2444d88426610c7f8a8d47fd1123eed55ba8c11c2444d8842
linuxlinux>= a8a572a6b5f2a79280d6e302cb3c1cb1fbaeb3e8 < 0f6ede9fbc747e2553612271bce108f7517e7a450f6ede9fbc747e2553612271bce108f7517e7a45
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 5.4.0-212.2325.4.0-212.232
linuxlinux_kernel>= 0 < 5.15.0-136.1475.15.0-136.147
linuxlinux_kernel>= 0 < 6.8.0-57.596.8.0-57.59

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.