CVE-2024-42272

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/08/2024
Last modified:
03/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> sched: act_ct: take care of padding in struct zones_ht_key<br /> <br /> Blamed commit increased lookup key size from 2 bytes to 16 bytes,<br /> because zones_ht_key got a struct net pointer.<br /> <br /> Make sure rhashtable_lookup() is not using the padding bytes<br /> which are not initialized.<br /> <br /> BUG: KMSAN: uninit-value in rht_ptr_rcu include/linux/rhashtable.h:376 [inline]<br /> BUG: KMSAN: uninit-value in __rhashtable_lookup include/linux/rhashtable.h:607 [inline]<br /> BUG: KMSAN: uninit-value in rhashtable_lookup include/linux/rhashtable.h:646 [inline]<br /> BUG: KMSAN: uninit-value in rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]<br /> BUG: KMSAN: uninit-value in tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329<br /> rht_ptr_rcu include/linux/rhashtable.h:376 [inline]<br /> __rhashtable_lookup include/linux/rhashtable.h:607 [inline]<br /> rhashtable_lookup include/linux/rhashtable.h:646 [inline]<br /> rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]<br /> tcf_ct_flow_table_get+0x611/0x2260 net/sched/act_ct.c:329<br /> tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408<br /> tcf_action_init_1+0x6cc/0xb30 net/sched/act_api.c:1425<br /> tcf_action_init+0x458/0xf00 net/sched/act_api.c:1488<br /> tcf_action_add net/sched/act_api.c:2061 [inline]<br /> tc_ctl_action+0x4be/0x19d0 net/sched/act_api.c:2118<br /> rtnetlink_rcv_msg+0x12fc/0x1410 net/core/rtnetlink.c:6647<br /> netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2550<br /> rtnetlink_rcv+0x34/0x40 net/core/rtnetlink.c:6665<br /> netlink_unicast_kernel net/netlink/af_netlink.c:1331 [inline]<br /> netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1357<br /> netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1901<br /> sock_sendmsg_nosec net/socket.c:730 [inline]<br /> __sock_sendmsg+0x30f/0x380 net/socket.c:745<br /> ____sys_sendmsg+0x877/0xb60 net/socket.c:2597<br /> ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2651<br /> __sys_sendmsg net/socket.c:2680 [inline]<br /> __do_sys_sendmsg net/socket.c:2689 [inline]<br /> __se_sys_sendmsg net/socket.c:2687 [inline]<br /> __x64_sys_sendmsg+0x307/0x4a0 net/socket.c:2687<br /> x64_sys_call+0x2dd6/0x3c10 arch/x86/include/generated/asm/syscalls_64.h:47<br /> do_syscall_x64 arch/x86/entry/common.c:52 [inline]<br /> do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83<br /> entry_SYSCALL_64_after_hwframe+0x77/0x7f<br /> <br /> Local variable key created at:<br /> tcf_ct_flow_table_get+0x4a/0x2260 net/sched/act_ct.c:324<br /> tcf_ct_init+0xa67/0x2890 net/sched/act_ct.c:1408

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.10.221 (including) 5.10.224 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.15.162 (including) 5.15.165 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.96 (including) 6.1.104 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.36 (including) 6.6.45 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.9.7 (including) 6.10 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.10 (including) 6.10.4 (excluding)
cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:*