CVE-2024-26951: wireguard: netlink: check for dangling peer via is_dead instead of empty list
In the Linux kernel, the following vulnerability has been resolved:
wireguard: netlink: check for dangling peer via isdead instead of empty list
If all peers are removed via wgpeerremoveall(), rather than setting peerlist to empty, the peer is added to a temporary list with a head on the stack of wgpeerremoveall(). If a netlink dump is resumed and the cursored peer is one that has been removed via wgpeerremoveall(), it will iterate from that peer and then attempt to dump freed peers.
Fix this by instead checking peer->isdead, which was explictly created for this purpose. Also move up the deviceupdatelock lockdep assertion, since reading isdead relies on that.
It can be reproduced by a small script like:
echo "Setting config..." ip link add dev wg0 type wireguard wg setconf wg0 /big-config ( while true; do echo "Showing config..." wg showconf wg0 > /dev/null done ) & sleep 4 wg setconf wg0 <(printf "[Peer]\nPublicKey=$(wg genkey)\n")
Resulting in:
BUG: KASAN: slab-use-after-free in lockacquire+0x182a/0x1b20 Read of size 8 at addr ffff88811956ec70 by task wg/59 CPU: 2 PID: 59 Comm: wg Not tainted 6.8.0-rc2-debug+ #5 Call Trace: <TASK> dumpstacklvl+0x47/0x70 printaddressdescription.constprop.0+0x2c/0x380 printreport+0xab/0x250 kasanreport+0xba/0xf0 lockacquire+0x182a/0x1b20 lockacquire+0x191/0x4b0 downread+0x80/0x440 getpeer+0x140/0xcb0 wggetdevicedump+0x471/0x1130
Other sources
In the Linux kernel, the following vulnerability has been resolved:
wireguard: netlink: check for dangling peer via isdead instead of empty list
The Linux kernel CVE team has assigned CVE-2024-26951 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024050127-CVE-2024-26951-5cbe@gregkh/T
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.133-1Fixed in 6.12.22-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.10.215 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.15.154 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.84 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.24 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.7.12 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8.3 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9 - Upgrade
Upgrade
Linux kernel (WireGuard: netlink)to a version that resolves this vulnerability.Patch CVE-2024-26951 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch wireguard: netlink: check for dangling peer via is_dead instead of empty list
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26951?
CVE-2024-26951 is considered a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2024-26951?
To fix CVE-2024-26951, update to kernel version 5.10.215 or later, 5.15.154 or later, 6.1.84 or later, 6.6.24 or later, 6.7.12 or later, 6.8.3 or later, or 6.9.
Which Linux distributions are affected by CVE-2024-26951?
CVE-2024-26951 affects Red Hat and Debian distributions that utilize specific kernel versions.
What components of the Linux kernel are impacted by CVE-2024-26951?
CVE-2024-26951 impacts the WireGuard component within the Linux kernel related to netlink handling.
Is there any exploit available for CVE-2024-26951?
As of now, there are no public reports of active exploits for CVE-2024-26951.