CVE-2024-40983: tipc: force a dst refcount before doing decryption
In the Linux kernel, the following vulnerability has been resolved:
tipc: force a dst refcount before doing decryption
As it says in commit 3bc07321ccc2 ("xfrm: Force a dst refcount before entering the xfrm type handlers"):
"Crypto requests might return asynchronous. In this case we leave the rcu protected region, so force a refcount on the skb's destination entry before we enter the xfrm type input/output handlers."
On TIPC decryption path it has the same problem, and skbdstforce() should be called before doing decryption to avoid a possible crash.
Shuang reported this issue when this warning is triggered:
[] WARNING: include/net/dst.h:337 tipcskrcv+0x1055/0x1ea0 [tipc] [] Kdump: loaded Tainted: G W --------- - - 4.18.0-496.el8.x8664+debug [] Workqueue: crypto cryptdqueueworker [] RIP: 0010:tipcskrcv+0x1055/0x1ea0 [tipc] [] Call Trace: [] tipcskmcastrcv+0x548/0xea0 [tipc] [] tipcrcv+0xcf5/0x1060 [tipc] [] tipcaeaddecryptdone+0x215/0x2e0 [tipc] [] cryptdaeadcrypt+0xdb/0x190 [] cryptdqueueworker+0xed/0x190 [] processonework+0x93d/0x17e0
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.10.221 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 5.15.162 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.1.96 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.6.36 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.9.7 - Upgrade
Upgrade
redhat/kernelto a version that resolves this vulnerability.Fixed in 6.10 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1 - Upgrade
Upgrade
Linux kernel (TIPC)to a version that resolves this vulnerability.Patch 3bc07321ccc2 - Compensating control
If not yet fixed via kernel update, ensure skb_dst_force() is called before TIPC decryption on the TIPC decryption path to force a dst refcount prior to entering decryption/xfrm handling, avoiding a possible crash.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-40983?
The severity of CVE-2024-40983 is not explicitly assigned, but it involves a vulnerability in the Linux kernel which can potentially affect system stability and security.
How do I fix CVE-2024-40983?
To fix CVE-2024-40983, you should update your Linux kernel to one of the remedied versions: 5.10.221, 5.15.162, 6.1.96, 6.6.36, 6.9.7, 6.10, or the specific Debian version updates.
Which Linux kernel versions are affected by CVE-2024-40983?
CVE-2024-40983 affects multiple kernel versions, specifically versions prior to 5.10.221, 5.15.162, 6.1.96, 6.6.36, 6.9.7, and 6.10.
Is my distribution vulnerable to CVE-2024-40983?
If you are using a version of the Linux kernel that is below the remedied versions listed, your distribution may be vulnerable to CVE-2024-40983.
What types of systems are impacted by CVE-2024-40983?
CVE-2024-40983 impacts any systems running the vulnerable Linux kernel versions, which can include servers, workstations, and embedded devices.