CVE-2024-44934·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: wait for previous gc cycles when removing port syzbot hit a use-after-free[1] which is caused because the bridge doesn't make sure that all previous garbage has been collected when removing a port. What happens is: CPU 1 CPU 2 start gc cycle remove port acquire gc lock first wait for lock call br_multicasg_gc() directly acquire lock now but free port the port can be freed while grp timers still running Make sure all previous gc cycles have finished by using flush_work before freeing the port. [1] BUG: KASAN: slab-use-after-free in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861 Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699 CPU: 1 PID: 9699 Comm: syz.5.1232 Not tainted 6.10.0-rc5-syzkaller-00021-g24ca36a562d6 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024 Call Trace: <IRQ> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0xc3/0x620 mm/kasan/report.c:488 kasan_report+0xd9/0x110 mm/kasan/report.c:601 br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861 call_timer_fn+0x1a3/0x610 kernel/time/timer.c:1792 expire_timers kernel/time/timer.c:1843 [inline] __run_timers+0x74b/0xaf0 kernel/time/timer.c:2417 __run_timer_base kernel/time/timer.c:2428 [inline] __run_timer_base kernel/time/timer.c:2421 [inline] run_timer_base+0x111/0x190 kernel/time/timer.c:2437
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.10.5
- Published
- 2024-08-26
Affected versions
From: 6.7
Until: 6.10.5
Fixed in: 6.10.5
How to fix this CVE
Update your Linux kernel to version 6.10.5 or later to resolve a use-after-free vulnerability in the bridge multicast garbage collection routine. This vulnerability occurs when a bridge port is removed while garbage collection timers are still active, potentially leading to memory corruption. Ensure you reboot after applying the kernel update to activate the patched version.
sudo dnf update kernel kernel-devel && sudo rebootDefensia detects this vulnerability
How to check if you are affected
- Check the current kernel version with: uname -r
- Verify the vulnerability affects your system by confirming kernel version is between 6.7 and 6.10.4: uname -r | awk -F'.' '{print $1"."$2"."$3}'
- Search kernel logs for multicast-related crashes with: dmesg | grep -i 'use-after-free\|br_multicast\|KASAN'
- Confirm the patched version is running after update with: uname -r (should show 6.10.5 or later)
FAQ
What is CVE-2024-44934?
CVE-2024-44934 is a use-after-free vulnerability in the Linux kernel's bridge multicast garbage collection mechanism. It allows memory corruption when a bridge port is removed while garbage collection timers are executing, potentially leading to privilege escalation or system crash.
Is CVE-2024-44934 being actively exploited?
No, CVE-2024-44934 is not listed in the CISA Known Exploited Vulnerabilities catalog and no public exploits have been disclosed. However, it requires local access and is high severity due to its impact on system stability.
What versions of Kernel are affected by CVE-2024-44934?
Linux kernel versions 6.7.0 through 6.10.4 are affected. Systems running kernel 6.10.5 or later, or versions before 6.7.0, are not vulnerable.
How do I check if my server is vulnerable to CVE-2024-44934?
Run: uname -r. If the output shows kernel version 6.7.x through 6.10.4, your system is vulnerable. Check if bridge networking is enabled with: cat /proc/net/bridge/br-* 2>/dev/null and look for multicast configuration.
Does Defensia detect CVE-2024-44934?
Yes — Defensia's CVE advisory scanner compares installed kernel versions against the NVD database. If a vulnerable kernel version is detected on a monitored server, CVE-2024-44934 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0d8b26e10e680c01522d7cc14abe04c3265a928f
- https://git.kernel.org/stable/c/1e16828020c674b3be85f52685e8b80f9008f50f
- https://git.kernel.org/stable/c/92c4ee25208d0f35dafc3213cdf355fbe449e078
- https://git.kernel.org/stable/c/b2f794b168cf560682ff976b255aa6d29d14a658
- https://git.kernel.org/stable/c/e3145ca904fa8dbfd1a5bf0187905bc117b0efce
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-44934. Free for 1 server.
Get started free