CVE-2024-42271·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: net/iucv: fix use after free in iucv_sock_close() iucv_sever_path() is called from process context and from bh context. iucv->path is used as indicator whether somebody else is taking care of severing the path (or it is already removed / never existed). This needs to be done with atomic compare and swap, otherwise there is a small window where iucv_sock_close() will try to work with a path that has already been severed and freed by iucv_callback_connrej() called by iucv_tasklet_fn(). Example: [452744.123844] Call Trace: [452744.123845] ([<0000001e87f03880>] 0x1e87f03880) [452744.123966] [<00000000d593001e>] iucv_path_sever+0x96/0x138 [452744.124330] [<000003ff801ddbca>] iucv_sever_path+0xc2/0xd0 [af_iucv] [452744.124336] [<000003ff801e01b6>] iucv_sock_close+0xa6/0x310 [af_iucv] [452744.124341] [<000003ff801e08cc>] iucv_sock_release+0x3c/0xd0 [af_iucv] [452744.124345] [<00000000d574794e>] __sock_release+0x5e/0xe8 [452744.124815] [<00000000d5747a0c>] sock_close+0x34/0x48 [452744.124820] [<00000000d5421642>] __fput+0xba/0x268 [452744.124826] [<00000000d51b382c>] task_work_run+0xbc/0xf0 [452744.124832] [<00000000d5145710>] do_notify_resume+0x88/0x90 [452744.124841] [<00000000d5978096>] system_call+0xe2/0x2c8 [452744.125319] Last Breaking-Event-Address: [452744.125321] [<00000000d5930018>] iucv_path_sever+0x90/0x138 [452744.125324] [452744.125325] Kernel panic - not syncing: Fatal exception in interrupt Note that bh_lock_sock() is not serializing the tasklet context against process context, because the check for sock_owned_by_user() and corresponding handling is missing. Ideas for a future clean-up patch: A) Correct usage of bh_lock_sock() in tasklet context, as described in Re-enqueue, if needed. This may require adding return values to the tasklet functions and thus changes to all users of iucv. B) Change iucv tasklet into worker and use only lock_sock() in af_iucv.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.4
- Published
- 2024-08-17
Affected versions
From: 6.7
Until: 6.10.4
Fixed in: 6.10.4
How to fix this CVE
Update your Linux kernel to version 6.10.4 or later to resolve a use-after-free vulnerability in the IUCV socket implementation that can cause kernel panics. This patch corrects the synchronization mechanism between process and tasklet contexts when severing IUCV paths, preventing access to freed memory. Affected systems running kernel versions 6.7 through 6.10.3 should prioritize this update.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check installed kernel version: uname -r (must be 6.10.4 or later; vulnerable if between 6.7.x and 6.10.3)
- Verify IUCV support is enabled: grep -i iucv /boot/config-$(uname -r) (look for CONFIG_AF_IUCV=y or CONFIG_AF_IUCV=m)
- Search kernel logs for IUCV-related panics: journalctl -k | grep -i 'iucv_path_sever\|Fatal exception in interrupt\|use after free'
- Confirm patch applied: git log --oneline --grep='iucv_sock_close' in kernel source, or verify kernel build timestamp is after the fix date
FAQ
What is CVE-2024-42271?
CVE-2024-42271 is a use-after-free vulnerability in the Linux kernel's IUCV (Inter-User Communication Vehicle) socket implementation. The flaw occurs due to inadequate synchronization when the kernel attempts to close a socket path that has already been freed by a concurrent tasklet callback, leading to kernel panic and potential denial of service.
Is CVE-2024-42271 being actively exploited?
No, CVE-2024-42271 is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are currently available. However, this is a high-severity vulnerability that can be triggered locally and should still be patched promptly.
What versions of Kernel are affected by CVE-2024-42271?
Linux kernel versions 6.7.0 through 6.10.3 are vulnerable. The vulnerability was fixed in kernel 6.10.4 and later stable releases.
How do I check if my server is vulnerable to CVE-2024-42271?
Run `uname -r` to check your kernel version. If the output shows a version between 6.7 and 6.10.3, your system is vulnerable. Also verify IUCV is enabled with `grep CONFIG_AF_IUCV /boot/config-$(uname -r)`.
Does Defensia detect CVE-2024-42271?
Yes — Defensia's CVE advisory scanner compares installed kernel versions against the NVD database. If a vulnerable kernel version (6.7–6.10.3) is detected on your monitored systems, CVE-2024-42271 will appear in your dashboard with detailed remediation guidance and patch availability.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/01437282fd3904810603f3dc98d2cac6b8b6fc84
- https://git.kernel.org/stable/c/37652fbef9809411cea55ea5fa1a170e299efcd0
- https://git.kernel.org/stable/c/69620522c48ce8215e5eb55ffbab8cafee8f407d
- https://git.kernel.org/stable/c/84f40b46787ecb67c7ad08a5bb1376141fa10c01
- https://git.kernel.org/stable/c/8b424c9e44111c5a76f41c6b741f8d4c4179d876
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-42271. Free for 1 server.
Get started free