CVE-2024-26898

CVSS v3.1 7.8 (High)
78% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 1
Advisories 45
NVD Status Modified

In the Linux kernel, the following vulnerability has been resolved:

aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts

This patch is against CVE-2023-6270. The description of cve is:

A flaw was found in the ATA over Ethernet (AoE) driver in the Linux
kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on
struct net_device, and a use-after-free can be triggered by racing
between the free on the struct and the access through the skbtxq
global queue. This could lead to a denial of service condition or
potential code execution.

In aoecmd_cfg_pkts(), it always calls dev_put(ifp) when skb initial
code is finished. But the net_device ifp will still be used in
later tx()->dev_queue_xmit() in kthread. Which means that the
dev_put(ifp) should NOT be called in the success path of skb
initial code in aoecmd_cfg_pkts(). Otherwise tx() may run into
use-after-free because the net_device is freed.

This patch removed the dev_put(ifp) in the success path in
aoecmd_cfg_pkts(), and added dev_put() after skb xmit in tx().

Weaknesses
CWE-416
Use After Free
Related CVEs
CVE Status
PUBLISHED
NVD Status
Modified
CNA
kernel.org
Published Date
2024-04-17 11:15:10
(5 months ago)
Updated Date
2024-08-01 13:48:14
(6 weeks ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.22 version and prior 4.19.311 version cpe:2.3:o:linux:linux_kernel >= 2.6.22 < 4.19.311
  Linux Kernel from 4.20 version and prior 5.4.273 version cpe:2.3:o:linux:linux_kernel >= 4.20 < 5.4.273
  Linux Kernel from 5.5 version and prior 5.10.214 version cpe:2.3:o:linux:linux_kernel >= 5.5 < 5.10.214
  Linux Kernel from 5.11 version and prior 5.15.153 version cpe:2.3:o:linux:linux_kernel >= 5.11 < 5.15.153
  Linux Kernel from 5.16 version and prior 6.1.83 version cpe:2.3:o:linux:linux_kernel >= 5.16 < 6.1.83
  Linux Kernel from 6.2 version and prior 6.6.23 version cpe:2.3:o:linux:linux_kernel >= 6.2 < 6.6.23
  Linux Kernel from 6.7 version and prior 6.7.11 version cpe:2.3:o:linux:linux_kernel >= 6.7 < 6.7.11
  Linux Kernel from 6.8 version and prior 6.8.2 version cpe:2.3:o:linux:linux_kernel >= 6.8 < 6.8.2
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...