CVE-2024-35894: mptcp: prevent BPF accessing lowat from a subflow socket.
In the Linux kernel, the following vulnerability has been resolved:
mptcp: prevent BPF accessing lowat from a subflow socket.
Alexei reported the following splat:
WARNING: CPU: 32 PID: 3276 at net/mptcp/subflow.c:1430 subflowdataready+0x147/0x1c0 Modules linked in: dummy bpftestmod(O) [last unloaded: bpftestnocfi(O)] CPU: 32 PID: 3276 Comm: testprogs Tainted: GO 6.8.0-12873-g2c43c33bfd23 Call Trace: <TASK> mptcpsetrcvlowat+0x79/0x1d0 sksetsockopt+0x6c0/0x1540 bpfsetsockopt+0x6f/0x90 bpfsockopssetsockopt+0x3c/0x90 bpfprog509ce5db2c7f9981bpftestsockoptint+0xb4/0x11b bpfprogdce07e362d941d2bbpftestsocketsockopt+0x12b/0x132 bpfprog348c9b5faaf10092skopssockopt+0x954/0xe86 cgroupbpfrunfiltersockops+0xbc/0x250 tcpconnect+0x879/0x1160 tcpv6connect+0x50c/0x870 mptcpconnect+0x129/0x280 inetstreamconnect+0xce/0x370 inetstreamconnect+0x36/0x50 bpftrampoline6442491565+0x49/0xef inetstreamconnect+0x5/0x50 sysconnect+0x63/0x90 x64sysconnect+0x14/0x20
The root cause of the issue is that bpf allows accessing mptcp-level protoops from a tcp subflow scope.
Fix the issue detecting the problematic call and preventing any action.
Other sources
In the Linux kernel, the following vulnerability has been resolved:
mptcp: prevent BPF accessing lowat from a subflow socket.
The Linux kernel CVE team has assigned CVE-2024-35894 to this issue.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024051949-CVE-2024-35894-fd19@gregkh/T
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.8.5 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2024-35894
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35894?
CVE-2024-35894 has a severity rating that indicates it can lead to potential denial-of-service conditions in affected Linux kernel versions.
How do I fix CVE-2024-35894?
The recommended fix for CVE-2024-35894 is to update the Linux kernel to versions 6.8.5 or 6.9.
Which Linux kernel versions are affected by CVE-2024-35894?
CVE-2024-35894 affects Linux kernel versions prior to 6.8.5 and includes certain pre-release versions of 6.9.
Who reported CVE-2024-35894?
CVE-2024-35894 was reported by an individual named Alexei.
What type of vulnerability is CVE-2024-35894?
CVE-2024-35894 is a vulnerability in the Linux kernel that affects the management of subflow sockets in multi-path TCP (MPTCP).