kernel: use-after-free in the XFRM subsystem related to an xfrm_state_fini() panic
Published Jun 7, 2021
7.8
HIGHCVSS 3.1
EPSS 0.50%
Description
An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46.
Affected products
No data.
Configuration 1
- < 5.0.19
Configuration 2
Running on/with
- n/a
Configuration 3
- n/a
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Configuration 16
- n/a
Configuration 17
- n/a
Configuration 18
- n/a
Configuration 19
- n/a
Configuration 20
Running on/with
- n/a
Configuration 21
- n/a
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is rated as having a Moderate impact because in the default configuration, the issue can only be triggered by a privileged local user. For the all versions of the Red Hat Enterprise Linux 8 the fix already applied, so not affected. For the Red Hat Enterprise Linux 7 the vulnerability not actual too, and it is known that XFRM subsystem vulnerabilities requires CAP_NET_ADMIN capability. In order to exploit this issue the attacker needs CAP_NET_ADMIN capability, which needs to be granted especially by the administrator to the attacker's process. This in turn requires granting CAP_NET_ADMIN capability to the process' binary and/or attacker's account. Another possibility to obtain CAP_NET_ADMIN capability in Red Hat Enterprise Linux 7 for an attacker is running a process inside a user+network namespace with mapped root privileges inside the namespace. Since Red Hat Enterprise Linux 7 does not have unprivileged user namespaces enabled by default, local or remote unprivileged users also cannot abuse namespaces to grant this capability to themselves and elevate their privileges.
References (9)
- https://access.redhat.com/security/cve/CVE-2019-25045 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1969541 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.19 x_refsource_MISCMailing ListRelease NotesVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=dbb2483b2a46fbaf833cfb5deb5ed9cace9c7399 x_refsource_MISCMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-25045
- https://security.netapp.com/advisory/ntap-20210720-0003/ x_refsource_CONFIRMThird Party Advisory
- https://sites.google.com/view/syzscope/warning-in-xfrm_state_fini-2 x_refsource_MISCExploitThird Party Advisory
- https://syzkaller.appspot.com/bug?id=f99edaeec58ad40380ed5813d89e205861be2896 x_refsource_MISCExploitMailing ListThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-25045
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-25045 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1969541 | Issue Tracking | |
| https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.0.19 | x_refsource_MISCMailing ListRelease NotesVendor Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=dbb2483b2a46fbaf833cfb5deb5ed9cace9c7399 | x_refsource_MISCMailing ListPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-25045 | ||
| https://security.netapp.com/advisory/ntap-20210720-0003/ | x_refsource_CONFIRMThird Party Advisory | |
| https://sites.google.com/view/syzscope/warning-in-xfrm_state_fini-2 | x_refsource_MISCExploitThird Party Advisory | |
| https://syzkaller.appspot.com/bug?id=f99edaeec58ad40380ed5813d89e205861be2896 | x_refsource_MISCExploitMailing ListThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2019-25045 |
Change history (0)
No recorded changes yet.