CVE-2024-45009: mptcp: pm: only decrement add_addr_accepted for MPJ req
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: only decrement addaddraccepted for MPJ req
Adding the following warning ...
WARNONONCE(msk->pm.addaddraccepted == 0)
... before decrementing the addaddraccepted counter helped to find a bug when running the "remove single subflow" subtest from the mptcpjoin.sh selftest.
Removing a 'subflow' endpoint will first trigger a RMADDR, then the subflow closure. Before this patch, and upon the reception of the RMADDR, the other peer will then try to decrement this addaddraccepted. That's not correct because the attached subflows have not been created upon the reception of an ADDADDR.
A way to solve that is to decrement the counter only if the attached subflow was an MPJOIN to a remote id that was not 0, and initiated by the host receiving the RMADDR.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45009?
The severity of CVE-2024-45009 is determined by its impact on the Linux kernel and its vulnerability to exploitation.
How do I fix CVE-2024-45009?
To fix CVE-2024-45009, update your Linux kernel to version 6.1.123-1 or one of the other remedied versions listed.
Which Linux kernel versions are affected by CVE-2024-45009?
CVE-2024-45009 affects Linux kernel versions between 5.10.223-1 and 5.10.226-1 as well as versions up to 5.15.167.
What component of the Linux kernel does CVE-2024-45009 impact?
CVE-2024-45009 impacts the MultiPath TCP (MPTCP) implementation in the Linux kernel.
Is CVE-2024-45009 related to potential denial of service vulnerabilities?
CVE-2024-45009 may be related to denial of service vulnerabilities due to issues in handling MPTCP address acceptance.