CVE-2024-27414: rtnetlink: fix error logic of IFLA_BRIDGE_FLAGS writing back
In the Linux kernel, the following vulnerability has been resolved:
rtnetlink: fix error logic of IFLABRIDGEFLAGS writing back
In the commit d73ef2d69c0d ("rtnetlink: let rtnlbridgesetlink checks IFLABRIDGEMODE length"), an adjustment was made to the old loop logic in the function rtnlbridgesetlink to enable the loop to also check the length of the IFLABRIDGEMODE attribute. However, this adjustment removed the break statement and led to an error logic of the flags writing back at the end of this function.
if (haveflags) memcpy(nladata(attr), &flags, sizeof(flags)); // attr should point to IFLABRIDGEFLAGS NLA !!!
Before the mentioned commit, the attr is granted to be IFLABRIDGEFLAGS. However, this is not necessarily true fow now as the updated loop will let the attr point to the last NLA, even an invalid NLA which could cause overflow writes.
This patch introduces a new variable brflag to save the NLA pointer that points to IFLABRIDGEFLAGS and uses it to resolve the mentioned error logic.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
rtnetlink: fix error logic of IFLABRIDGEFLAGS writing back
The Linux kernel CVE team has assigned CVE-2024-27414 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024051702-CVE-2024-27414-5c5d@gregkh/T
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.4.271 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.10.212 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.15.151 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.81 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.21 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.7.9 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch d73ef2d69c0d - Compensating control
Apply the fix for rtnetlink error logic of IFLA_BRIDGE_FLAGS writing back in the Linux kernel commit d73ef2d69c0d (CVE-2024-27414), which introduces br_flag to save the NLA pointer for IFLA_BRIDGE_FLAGS and prevents overflow/invalid NLA overwrite in rtnl_bridge_setlink.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27414?
CVE-2024-27414 has not been assigned a specific CVSS score, but it is classified as a vulnerability in the Linux kernel that could affect security mechanisms.
How do I fix CVE-2024-27414?
To resolve CVE-2024-27414, update your Linux kernel to version 5.4.271, 5.10.212, 5.15.151, 6.1.81, 6.6.21, 6.7.9, 6.8, or apply the appropriate patches provided by your distribution.
Which Linux kernel versions are affected by CVE-2024-27414?
CVE-2024-27414 affects various versions of the Linux kernel prior to the specified remedies including 5.4.271, 5.10.212, 5.15.151, and others listed in the patch notes.
What component of the Linux kernel is affected by CVE-2024-27414?
CVE-2024-27414 specifically concerns the rtnetlink component of the Linux kernel, particularly the logic of IFLA_BRIDGE_FLAGS.
Is CVE-2024-27414 exploitable remotely?
The details on remote exploitation potential for CVE-2024-27414 are not explicitly disclosed, but vulnerabilities in kernel components generally warrant caution.