CVE-2022-49094: net/tls: fix slab-out-of-bounds bug in decrypt_internal
In the Linux kernel, the following vulnerability has been resolved:
net/tls: fix slab-out-of-bounds bug in decryptinternal
The memory size of tlsctx->rx.iv for AES128-CCM is 12 setting in tlssetswoffload(). The return value of cryptoaeadivsize() for "ccm(aes)" is 16. So memcpy() require 16 bytes from 12 bytes memory space will trigger slab-out-of-bounds bug as following:
================================================================== BUG: KASAN: slab-out-of-bounds in decryptinternal+0x385/0xc40 [tls] Read of size 16 at addr ffff888114e84e60 by task tls/10911
Call Trace: <TASK> dumpstacklvl+0x34/0x44 printreport.cold+0x5e/0x5db ? decryptinternal+0x385/0xc40 [tls] kasanreport+0xab/0x120 ? decryptinternal+0x385/0xc40 [tls] kasancheckrange+0xf9/0x1e0 memcpy+0x20/0x60 decryptinternal+0x385/0xc40 [tls] ? tlsgetrec+0x2e0/0x2e0 [tls] ? processrxlist+0x1a5/0x420 [tls] ? tlssetupfromiter.constprop.0+0x2e0/0x2e0 [tls] decryptskbupdate+0x9d/0x400 [tls] tlsswrecvmsg+0x3c8/0xb50 [tls]
Allocated by task 10911: kasansavestack+0x1e/0x40 kasankmalloc+0x81/0xa0 tlssetswoffload+0x2eb/0xa20 [tls] tlssetsockopt+0x68c/0x700 [tls] syssetsockopt+0xfe/0x1b0
Replace the cryptoaeadivsize() with prot->ivsize + prot->saltsize when memcpy() iv value in TLS13VERSION scenario.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernel (net/tls)to a version that resolves this vulnerability.Patch net/tls: fix slab-out-of-bounds bug in decrypt_internal
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The affected path is the Linux kernel TLS receive/decryption path when AES128-CCM is used with TLS software offload. The issue arises because the receive IV buffer is 12 bytes while the CCM AEAD implementation reports a 16-byte IV size.
What does an attacker need to exploit it?
The supplied CVSS vector rates the issue as network-accessible, requiring low attack complexity, no privileges, and no user interaction. The provided information does not specify the exact TLS traffic or session conditions needed to trigger the faulty decrypt path.
What is the potential security impact?
The vulnerability is rated critical with a 9.8 CVSS score and high impacts on confidentiality, integrity, and availability. The described behavior is an out-of-bounds memory read in the kernel TLS module.