CVE-2024-50142

MEDIUM

Linux Kernel < 4.19.323, 4.20.0-6.11.6 - DoS via XFRM SA Prefix Length Validation Bypass

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: validate new SA's prefixlen using SA family when sel.family is unset This expands the validation introduced in commit 07bf7908950a ("xfrm: Validate address prefix lengths in the xfrm selector.") syzbot created an SA with usersa.sel.family = AF_UNSPEC usersa.sel.prefixlen_s = 128 usersa.family = AF_INET Because of the AF_UNSPEC selector, verify_newsa_info doesn't put limits on prefixlen_{s,d}. But then copy_from_user_state sets x->sel.family to usersa.family (AF_INET). Do the same conversion in verify_newsa_info before validating prefixlen_{s,d}, since that's how prefixlen is going to be used later on.

Scores

CVSS v3 5.5
EPSS 0.0026
EPSS Percentile 17.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (27)
linux/Kernel 2.6.12 - 4.19.323linux
linux/Kernel 4.20.0 - 5.4.285linux
linux/Kernel 5.11.0 - 5.15.170linux
linux/Kernel 5.16.0 - 6.1.115linux
linux/Kernel 5.5.0 - 5.10.229linux
linux/Kernel 6.2.0 - 6.6.59linux
linux/Kernel 6.7.0 - 6.11.6linux
Linux/Linux < 2.6.12
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 2d08a6c31c65f23db71a5385ee9cf9d8f9a67a71
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 3f0ab59e6537c6a8f9e1b355b48f9c05a76e8563
... and 17 more
Published Nov 07, 2024
Tracked Since Feb 18, 2026