CVE-2024-36972: af_unix: Update unix_sk(sk)->oob_skb under sk_receive_queue lock.

Published Jun 10, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

afunix: Update unixsk(sk)->oobskb under skreceivequeue lock.

Billy Jheng Bing-Jhong reported a race between unixgc() and queueoob().

unixgc() tries to garbage-collect close()d inflight sockets, and then if the socket has MSGOOB in unixsk(sk)->oobskb, GC will drop the reference and set NULL to it locklessly.

However, the peer socket still can send MSGOOB message and queueoob() can update unixsk(sk)->oobskb concurrently, leading NULL pointer dereference. [0]

To fix the issue, let's update unixsk(sk)->oobskb under the skreceivequeue's lock and take it everywhere we touch oobskb.

Note that we defer kfreeskb() in manageoob() to silence lockdep false-positive (See [1]).

[0]: BUG: kernel NULL pointer dereference, address: 0000000000000008 PF: supervisor write access in kernel mode PF: errorcode(0x0002) - not-present page PGD 8000000009f5e067 P4D 8000000009f5e067 PUD 9f5d067 PMD 0 Oops: 0002 [#1] PREEMPT SMP PTI CPU: 3 PID: 50 Comm: kworker/3:1 Not tainted 6.9.0-rc5-00191-gd091e579b864 #110 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 Workqueue: events delayedfput RIP: 0010:skbdequeue (./include/linux/skbuff.h:2386 ./include/linux/skbuff.h:2402 net/core/skbuff.c:3847) Code: 39 e3 74 3e 8b 43 10 48 89 ef 83 e8 01 89 43 10 49 8b 44 24 08 49 c7 44 24 08 00 00 00 00 49 8b 14 24 49 c7 04 24 00 00 00 00 <48> 89 42 08 48 89 10 e8 e7 c5 42 00 4c 89 e0 5b 5d 41 5c c3 cc cc RSP: 0018:ffffc900001bfd48 EFLAGS: 00000002 RAX: 0000000000000000 RBX: ffff8880088f5ae8 RCX: 00000000361289f9 RDX: 0000000000000000 RSI: 0000000000000206 RDI: ffff8880088f5b00 RBP: ffff8880088f5b00 R08: 0000000000080000 R09: 0000000000000001 R10: 0000000000000003 R11: 0000000000000001 R12: ffff8880056b6a00 R13: ffff8880088f5280 R14: 0000000000000001 R15: ffff8880088f5a80 FS: 0000000000000000(0000) GS:ffff88807dd80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000008 CR3: 0000000006314000 CR4: 00000000007506f0 PKRU: 55555554 Call Trace: <TASK> unixreleasesock (net/unix/afunix.c:654) unixrelease (net/unix/afunix.c:1050) sockrelease (net/socket.c:660) sockclose (net/socket.c:1423) fput (fs/filetable.c:423) delayedfput (fs/filetable.c:444 (discriminator 3)) processonework (kernel/workqueue.c:3259) workerthread (kernel/workqueue.c:3329 kernel/workqueue.c:3416) kthread (kernel/kthread.c:388) retfromfork (arch/x86/kernel/process.c:153) retfromforkasm (arch/x86/entry/entry64.S:257) </TASK> Modules linked in: CR2: 0000000000000008

Affected Software

6 affected componentsFixes available
Google Android
Linux Linux Kernel>=5.15.149<5.15.161
Linux Linux Kernel>=6.1.78<6.1.93
Linux Linux Kernel>=6.6.17<6.6.33
Linux Linux Kernel>=6.7.5<6.9.4
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1

Event History

Jun 10, 2024
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
DescriptionSeverity
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 11, 2024
Data Sourced
via Launchpad·04:24 PM
Description
Nov 30, 2024
Data Sourced
via Ubuntu·04:43 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-36972?

CVE-2024-36972 has been classified with a medium severity rating involving a race condition in the Linux kernel.

2

How do I fix CVE-2024-36972?

To fix CVE-2024-36972, upgrade to the appropriate patched versions of the Linux kernel, including 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, or 6.12.11-1.

3

What systems are affected by CVE-2024-36972?

CVE-2024-36972 affects Linux kernel versions that include the specific fixes related to the unix_sk structure.

4

Who reported CVE-2024-36972?

CVE-2024-36972 was reported by Billy Jheng Bing-Jhong.

5

What is the nature of the issue in CVE-2024-36972?

CVE-2024-36972 involves a race condition between garbage collection and socket queuing in the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203