7.8

CVE-2024-41042

netfilter: nf_tables: prefer nft_chain_validate

In the Linux kernel, the following vulnerability has been resolved:

netfilter: nf_tables: prefer nft_chain_validate

nft_chain_validate already performs loop detection because a cycle will
result in a call stack overflow (ctx->level >= NFT_JUMP_STACK_SIZE).

It also follows maps via ->validate callback in nft_lookup, so there
appears no reason to iterate the maps again.

nf_tables_check_loops() and all its helper functions can be removed.
This improves ruleset load time significantly, from 23s down to 12s.

This also fixes a crash bug. Old loop detection code can result in
unbounded recursion:

BUG: TASK stack guard page was hit at ....
Oops: stack guard page: 0000 [#1] PREEMPT SMP KASAN
CPU: 4 PID: 1539 Comm: nft Not tainted 6.10.0-rc5+ #1
[..]

with a suitable ruleset during validation of register stores.

I can't see any actual reason to attempt to check for this from
nft_validate_register_store(), at this point the transaction is still in
progress, so we don't have a full picture of the rule graph.

For nf-next it might make sense to either remove it or make this depend
on table->validate_state in case we could catch an error earlier
(for improved error reporting to userspace).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 3.13 < 4.19.320
Linux ≫ Linux Kernel Version >= 4.20 < 5.4.282
Linux ≫ Linux Kernel Version >= 5.5 < 5.10.224
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.165
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.105
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.46
Linux ≫ Linux Kernel Version >= 6.7 < 6.9.10
Linux ≫ Linux Kernel Version 6.10 Update rc1
Linux ≫ Linux Kernel Version 6.10 Update rc2
Linux ≫ Linux Kernel Version 6.10 Update rc3
Linux ≫ Linux Kernel Version 6.10 Update rc4
Linux ≫ Linux Kernel Version 6.10 Update rc5
Linux ≫ Linux Kernel Version 6.10 Update rc6
Linux ≫ Linux Kernel Version 6.10 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.236
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://git.kernel.org/stable/c/1947e4c3346faa8ac7e343652c0fd3b3e394202f
Patch
https://git.kernel.org/stable/c/31c35f9f89ef585f1edb53e17ac73a0ca4a9712b
Patch
https://git.kernel.org/stable/c/717c91c6ed73e248de6a15bc53adefb81446c9d0
Patch
https://git.kernel.org/stable/c/8246b7466c8da49d0d9e85e26cbd69dd6d3e3d1e
Patch
https://git.kernel.org/stable/c/9df785aeb7dcc8efd1d4110bb27d26005298ebae
Patch
https://git.kernel.org/stable/c/b6b6e430470e1c3c5513311cb35a15a205595abe
Patch
https://git.kernel.org/stable/c/cd4348e0a50286282c314ad6d2b0740e7c812c24
Patch
https://git.kernel.org/stable/c/cff3bd012a9512ac5ed858d38e6ed65f6391008c
Patch
https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html
https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html