CVE-2024-42272
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/08/2024
Last modified:
03/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
sched: act_ct: take care of padding in struct zones_ht_key<br />
<br />
Blamed commit increased lookup key size from 2 bytes to 16 bytes,<br />
because zones_ht_key got a struct net pointer.<br />
<br />
Make sure rhashtable_lookup() is not using the padding bytes<br />
which are not initialized.<br />
<br />
BUG: KMSAN: uninit-value in rht_ptr_rcu include/linux/rhashtable.h:376 [inline]<br />
BUG: KMSAN: uninit-value in __rhashtable_lookup include/linux/rhashtable.h:607 [inline]<br />
BUG: KMSAN: uninit-value in rhashtable_lookup include/linux/rhashtable.h:646 [inline]<br />
BUG: KMSAN: uninit-value in rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]<br />
BUG: KMSAN: uninit-value in tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329<br />
rht_ptr_rcu include/linux/rhashtable.h:376 [inline]<br />
__rhashtable_lookup include/linux/rhashtable.h:607 [inline]<br />
rhashtable_lookup include/linux/rhashtable.h:646 [inline]<br />
rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]<br />
tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329<br />
tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408<br />
tcf_action_init_1+0x6cc/0xb30 net/sched/act_api.c:1425<br />
tcf_action_init+0x458/0xf00 net/sched/act_api.c:1488<br />
tcf_action_add net/sched/act_api.c:2061 [inline]<br />
tc_ctl_action+0x4be/0x19d0 net/sched/act_api.c:2118<br />
rtnetlink_rcv_msg+0x12fc/0x1410 net/core/rtnetlink.c:6647<br />
netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2550<br />
rtnetlink_rcv+0x34/0x40 net/core/rtnetlink.c:6665<br />
netlink_unicast_kernel net/netlink/af_netlink.c:1331 [inline]<br />
netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1357<br />
netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1901<br />
sock_sendmsg_nosec net/socket.c:730 [inline]<br />
__sock_sendmsg+0x30f/0x380 net/socket.c:745<br />
____sys_sendmsg+0x877/0xb60 net/socket.c:2597<br />
___sys_sendmsg+0x28d/0x3c0 net/socket.c:2651<br />
__sys_sendmsg net/socket.c:2680 [inline]<br />
__do_sys_sendmsg net/socket.c:2689 [inline]<br />
__se_sys_sendmsg net/socket.c:2687 [inline]<br />
__x64_sys_sendmsg+0x307/0x4a0 net/socket.c:2687<br />
x64_sys_call+0x2dd6/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:47<br />
do_syscall_x64 arch/x86/entry/common.c:52 [inline]<br />
do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83<br />
entry_SYSCALL_64_after_hwframe+0x77/0x7f<br />
<br />
Local variable key created at:<br />
tcf_ct_flow_table_get+0x4a/0x2260 net/sched/act_ct.c:324<br />
tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10.221 (including) | 5.10.224 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.15.162 (including) | 5.15.165 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.1.96 (including) | 6.1.104 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.6.36 (including) | 6.6.45 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.9.7 (including) | 6.10 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.10 (including) | 6.10.4 (excluding) |
| cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/2191a54f63225b548fd8346be3611c3219a24738
- https://git.kernel.org/stable/c/3a5b68869dbe14f1157c6a24ac71923db060eeab
- https://git.kernel.org/stable/c/3ddefcb8f75e312535e2e7d5fef9932019ba60f2
- https://git.kernel.org/stable/c/7c03ab555eb1ba26c77fd7c25bdf44a0ac23edee
- https://git.kernel.org/stable/c/d06daf0ad645d9225a3ff6958dd82e1f3988fa64
- https://git.kernel.org/stable/c/d7cc186d0973afce0e1237c37f7512c01981fb79
- https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html



