From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1A3B317106F for ; Fri, 21 Jun 2024 10:25:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718965527; cv=none; b=Z8uRoKVqyF9lwoLOhVYh5tU0wqXRK+SgGBuYGLkQnVmKGc1RFGb5GrhJ92noL6XTTLl1VpNN8pe5mD/JTQ0gqDz1u+B+TbxmUA2heNm+jBuOX7J+UxgW48aUfh/SOg4wgNgK4dh0Ss3lSJY5EIPAuC6FQ3E5SI+PKvOBxqBLVes= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1718965527; c=relaxed/simple; bh=h/YXK2bCNK497lfL+ffWi0TZ2y2t3n+RB6in9hEI4dk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=kEiAEXDQI23cuZtOtS3UlLzJCchkOkb6YTax7m1MFpWVbR6z90W0FbGOzSjTSsiKjm+o6pi/kvVFQVpdolkksXw3Nx8UV2Z4H93LbYfLZGcBuvG7AMusD+ZQdxj416Vg9gkHmjRacjYUmDOBn49FCDVVrGvSEnZnm3V2L/EP2UE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=mzQxTbdg; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="mzQxTbdg" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8B80EC2BBFC; Fri, 21 Jun 2024 10:25:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1718965526; bh=h/YXK2bCNK497lfL+ffWi0TZ2y2t3n+RB6in9hEI4dk=; h=From:To:Cc:Subject:Date:Reply-to:From; b=mzQxTbdgiiDM5TF26RUPwuZX8Lhwy7TNnqdLlSxQ9wXXQIiUqdwn+j+r8Z6kwRrSt PCSTR1Z3gUMrYCVi3KvxH7mw6G+InHpDI7Vcnv6fZpb6utvFhzHF/Q5N/pGU0CQnYT FWGx56dR+au6kgR/bHtNu8V4qh8nzkV5Xt1xdzmA= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2024-36484: net: relax socket state check at accept time. Date: Fri, 21 Jun 2024 12:19:39 +0200 Message-ID: <2024062136-CVE-2024-36484-375b@gregkh> X-Mailer: git-send-email 2.45.2 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=4995; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=h/YXK2bCNK497lfL+ffWi0TZ2y2t3n+RB6in9hEI4dk=; b=owGbwMvMwCRo6H6F97bub03G02pJDGmlwTtaG1ncZp+2DjhiqOhQ+Pp8068/LwW707JkT33aO Psqb2dwRywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAEzEJplhwd4JehwvrxqdqKvx X/lvZ2vwVmYDDYb5Zf6BJU9nX2UtvP/+s2TDAktfvpfrAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: net: relax socket state check at accept time. Christoph reported the following splat: WARNING: CPU: 1 PID: 772 at net/ipv4/af_inet.c:761 __inet_accept+0x1f4/0x4a0 Modules linked in: CPU: 1 PID: 772 Comm: syz-executor510 Not tainted 6.9.0-rc7-g7da7119fe22b #56 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014 RIP: 0010:__inet_accept+0x1f4/0x4a0 net/ipv4/af_inet.c:759 Code: 04 38 84 c0 0f 85 87 00 00 00 41 c7 04 24 03 00 00 00 48 83 c4 10 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc e8 ec b7 da fd <0f> 0b e9 7f fe ff ff e8 e0 b7 da fd 0f 0b e9 fe fe ff ff 89 d9 80 RSP: 0018:ffffc90000c2fc58 EFLAGS: 00010293 RAX: ffffffff836bdd14 RBX: 0000000000000000 RCX: ffff888104668000 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: dffffc0000000000 R08: ffffffff836bdb89 R09: fffff52000185f64 R10: dffffc0000000000 R11: fffff52000185f64 R12: dffffc0000000000 R13: 1ffff92000185f98 R14: ffff88810754d880 R15: ffff8881007b7800 FS: 000000001c772880(0000) GS:ffff88811b280000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fb9fcf2e178 CR3: 00000001045d2002 CR4: 0000000000770ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: inet_accept+0x138/0x1d0 net/ipv4/af_inet.c:786 do_accept+0x435/0x620 net/socket.c:1929 __sys_accept4_file net/socket.c:1969 [inline] __sys_accept4+0x9b/0x110 net/socket.c:1999 __do_sys_accept net/socket.c:2016 [inline] __se_sys_accept net/socket.c:2013 [inline] __x64_sys_accept+0x7d/0x90 net/socket.c:2013 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0x58/0x100 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x76/0x7e RIP: 0033:0x4315f9 Code: fd ff 48 81 c4 80 00 00 00 e9 f1 fe ff ff 0f 1f 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 0f 83 ab b4 fd ff c3 66 2e 0f 1f 84 00 00 00 00 RSP: 002b:00007ffdb26d9c78 EFLAGS: 00000246 ORIG_RAX: 000000000000002b RAX: ffffffffffffffda RBX: 0000000000400300 RCX: 00000000004315f9 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000004 RBP: 00000000006e1018 R08: 0000000000400300 R09: 0000000000400300 R10: 0000000000400300 R11: 0000000000000246 R12: 0000000000000000 R13: 000000000040cdf0 R14: 000000000040ce80 R15: 0000000000000055 The reproducer invokes shutdown() before entering the listener status. After commit 94062790aedb ("tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets"), the above causes the child to reach the accept syscall in FIN_WAIT1 status. Eric noted we can relax the existing assertion in __inet_accept() The Linux kernel CVE team has assigned CVE-2024-36484 to this issue. Affected and fixed versions =========================== Issue introduced in 6.1.91 with commit 3fe4ef0568a4 and fixed in 6.1.93 with commit c09ddc605893 Issue introduced in 6.6.31 with commit f47d0d32fa94 and fixed in 6.6.33 with commit 87bdc9f6f58b Issue introduced in 6.9 with commit 94062790aedb and fixed in 6.9.4 with commit 5f9a04a94fd1 Issue introduced in 6.9 with commit 94062790aedb and fixed in 6.10-rc1 with commit 26afda78cda3 Issue introduced in 4.19.314 with commit 34e41a031fd7 Issue introduced in 5.4.276 with commit ed5e279b69e0 Issue introduced in 5.10.217 with commit 413c33b9f3bc Issue introduced in 5.15.159 with commit 2552c9d9440f Issue introduced in 6.8.10 with commit cbf232ba11bc Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2024-36484 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/ipv4/af_inet.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/c09ddc605893df542c6cf8dde6a57a93f7cf0adb https://git.kernel.org/stable/c/87bdc9f6f58b4417362d6932b49b828e319f97dc https://git.kernel.org/stable/c/5f9a04a94fd1894d7009055ab8e5832a0242dba3 https://git.kernel.org/stable/c/26afda78cda3da974fd4c287962c169e9462c495