Use-after-free in Linux kernel's ipv4: igmp component
Published Dec 19, 2023
7.8
HIGHCVSS 3.1
EPSS 0.37%
Description
A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation.
A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.
We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1.
Affected products
-
- Version 2.6.12StatusaffectedConstraints<6.7
- Version
- 10.0
- < 4.14.332
- ≥ 4.15 · < 4.19.301
- ≥ 4.20 · < 5.4.263
- ≥ 5.5 · < 5.10.203
- ≥ 5.11 · < 5.15.142
- ≥ 5.16 · < 6.1.66
- ≥ 6.2 · < 6.6.5
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.el8_10
Fixed · RHSA-2024:3138
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.rt7.342.el8_10
Fixed · RHSA-2024:2950
Red Hat Enterprise Linux 8.6 Extended Update Support
kernel-0:4.18.0-372.91.1.el8_6
Fixed · RHSA-2024:0724
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.51.1.el8_8
Fixed · RHSA-2024:1404
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.13.1.el9_4
Fixed · RHSA-2024:2394
Red Hat Enterprise Linux 9
kernel-0:5.14.0-427.13.1.el9_4
Fixed · RHSA-2024:2394
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-0:5.14.0-70.93.2.el9_0
Fixed · RHSA-2024:1250
Red Hat Enterprise Linux 9.0 Extended Update Support
kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0
Fixed · RHSA-2024:1306
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-0:5.14.0-284.52.1.el9_2
Fixed · RHSA-2024:0723
Red Hat Enterprise Linux 9.2 Extended Update Support
kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2
Fixed · RHSA-2024:0725
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8
kernel-0:4.18.0-372.91.1.el8_6
Fixed · RHSA-2024:0724
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.el8_10 | Fixed | RHSA-2024:3138 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.rt7.342.el8_10 | Fixed | RHSA-2024:2950 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | kernel-0:4.18.0-372.91.1.el8_6 | Fixed | RHSA-2024:0724 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.51.1.el8_8 | Fixed | RHSA-2024:1404 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.13.1.el9_4 | Fixed | RHSA-2024:2394 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-427.13.1.el9_4 | Fixed | RHSA-2024:2394 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-0:5.14.0-70.93.2.el9_0 | Fixed | RHSA-2024:1250 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | kernel-rt-0:5.14.0-70.93.1.rt21.165.el9_0 | Fixed | RHSA-2024:1306 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-0:5.14.0-284.52.1.el9_2 | Fixed | RHSA-2024:0723 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | kernel-rt-0:5.14.0-284.52.1.rt14.337.el9_2 | Fixed | RHSA-2024:0725 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 | kernel-0:4.18.0-372.91.1.el8_6 | Fixed | RHSA-2024:0724 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability poses a moderate severity risk due to its potential to trigger a use-after-free issue when processing IGMPv2 query packets under specific conditions. An attacker could exploit this flaw by continuously sending crafted IGMPv2 query packets to a vulnerable system, causing a reference count underflow in the multicast group list management. Subsequently, this could lead to a use-after-free scenario, potentially resulting in a denial-of-service condition or other adverse effects. While exploitation requires specific configurations and continuous packet transmission, the impact could be significant, warranting attention and remediation to prevent potential exploitation and system instability.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- http://packetstormsecurity.com/files/177029/Kernel-Live-Patch-Security-Notice-LSN-0100-1.html Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-6932 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2255283 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-398330.html
- https://cert-portal.siemens.com/productcert/html/ssa-613116.html
- https://cert-portal.siemens.com/productcert/html/ssa-794697.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59130 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=e2b706c691905fe78468c361aaabc719d0a496f1 patchMailing List
- https://kernel.dance/e2b706c691905fe78468c361aaabc719d0a496f1 Patch
- https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-6932
- https://www.cve.org/CVERecord?id=CVE-2023-6932
Change history (0)
No recorded changes yet.