mac802154: Fix potential RCU dereference issue in mac802154_scan_worker
Published Oct 21, 2024
7.8
HIGHCVSS 3.1
EPSS 0.22%
Description
In the `mac802154_scan_worker` function, the `scan_req->type` field was accessed after the RCU read-side critical section was unlocked. According to RCU usage rules, this is illegal and can lead to unpredictable behavior, such as accessing memory that has been updated or causing use-after-free issues.
This possible bug was identified using a static analysis tool developed by myself, specifically designed to detect RCU-related issues.
To address this, the `scan_req->type` value is now stored in a local variable `scan_req_type` while still within the RCU read-side critical section. The `scan_req_type` is then used after the RCU lock is released, ensuring that the type value is safely accessed without violating RCU rules.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.5StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.5
- Version 6.10.14StatusunaffectedConstraints<=6.10.*
- Version 6.11.3StatusunaffectedConstraints<=6.11.*
- Version 6.12StatusunaffectedConstraints<=*
- Version 6.6.55StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.5 · < 6.6.55
- ≥ 6.7 · < 6.10.14
- ≥ 6.11 · < 6.11.3
- 6.12
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2024-50005 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2320580 Issue Tracking
- https://git.kernel.org/stable/c/540138377b22f601f06f55ebfa3ca171dcab471a Patch
- https://git.kernel.org/stable/c/bff1709b3980bd7f80be6786f64cc9a9ee9e56da Patch
- https://git.kernel.org/stable/c/d18f669461811dfe2915d5554ab2a9834f810013 Patch
- https://git.kernel.org/stable/c/e676e4ea76bbe7f1156d8c326b9b6753849481c2 Patch
- https://lore.kernel.org/linux-cve-announce/2024102108-CVE-2024-50005-3479@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-50005
- https://www.cve.org/CVERecord?id=CVE-2024-50005
Change history (0)
No recorded changes yet.