bpf: Fix a potential use-after-free in bpf_link_free()
Published Jul 12, 2024
7.8
HIGHCVSS 3.1
EPSS 0.28%
Description
After commit 1a80dbcb2dba, bpf_link can be freed by link->ops->dealloc_deferred, but the code still tests and uses link->ops->dealloc afterward, which leads to a use-after-free as reported by syzbot. Actually, one of them should be sufficient, so just call one of them instead of both. Also add a WARN_ON() in case of any problematic implementation.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version
-
- Version 6.6.26StatusaffectedConstraints<6.6.35
- Version 6.8.5StatusaffectedConstraints<6.9
- Version
-
- Version 6.9StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.9
- Version 6.10StatusunaffectedConstraints<=*
- Version 6.6.35StatusunaffectedConstraints<=6.6.*
- Version 6.9.6StatusunaffectedConstraints<=6.9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 6.6.26 · < 6.6.35
- ≥ 6.9 · < 6.9.6
- 6.10
- 6.10
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Linux is not vulnerable to this CVE, as it does not affect the versions or configurations of the Linux kernel used in its distributions.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2024-40909 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297493 Issue Tracking
- https://git.kernel.org/stable/c/2884dc7d08d98a89d8d65121524bb7533183a63a Patch
- https://git.kernel.org/stable/c/91cff53136daeff50816b0baeafd38a6976f6209 Patch
- https://git.kernel.org/stable/c/fa97b8fed9896f1e89cb657513e483a152d4c382 Patch
- https://lore.kernel.org/linux-cve-announce/2024071210-CVE-2024-40909-1706@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-40909
- https://www.cve.org/CVERecord?id=CVE-2024-40909
Change history (0)
No recorded changes yet.