Back

HIGH

tipc: re-fetch skb cb after tipc_msg_validate

Published Oct 21, 2024

Description

As the call trace shows, the original skb was freed in tipc_msg_validate(), and dereferencing the old skb cb would cause an use-after-free crash.

BUG: KASAN: use-after-free in tipc_crypto_rcv_complete+0x1835/0x2240 [tipc] Call Trace: <IRQ> tipc_crypto_rcv_complete+0x1835/0x2240 [tipc] tipc_crypto_rcv+0xd32/0x1ec0 [tipc] tipc_rcv+0x744/0x1150 [tipc] ... Allocated by task 47078: kmem_cache_alloc_node+0x158/0x4d0 __alloc_skb+0x1c1/0x270 tipc_buf_acquire+0x1e/0xe0 [tipc] tipc_msg_create+0x33/0x1c0 [tipc] tipc_link_build_proto_msg+0x38a/0x2100 [tipc] tipc_link_timeout+0x8b8/0xef0 [tipc] tipc_node_timeout+0x2a1/0x960 [tipc] call_timer_fn+0x2d/0x1c0 ... Freed by task 47078: tipc_msg_validate+0x7b/0x440 [tipc] tipc_crypto_rcv_complete+0x4b5/0x2240 [tipc] tipc_crypto_rcv+0xd32/0x1ec0 [tipc] tipc_rcv+0x744/0x1150 [tipc]

This patch fixes it by re-fetching the skb cb from the new allocated skb after calling tipc_msg_validate().

Affected products

Remediation

Red Hat statement

This issue is considered to be a moderate impact flaw, as the reproducer for this issue is not available to cause an Intigrity (I:L) threat. The bug could happen only if TIPC encryption being used. Being used as Inter-process Communication (IPC) service for cluster-wide operation. Actual only for latest versions of Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 9.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026
Reserved Aug 22, 2024
CISA Vulnrichment
Updated Oct 22, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Oct 21, 2024
ENISA EUVD
Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026
Exploited since n/a
EUVD-2022-53901