PT-2024-21493 · Linux · Linux Kernel

Syzbot

·

Published

2024-02-21

·

Updated

2025-02-03

·

CVE-2024-26732

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b
Description A vulnerability has been resolved in the Linux kernel, specifically in the net subsystem, where a lockdep violation was reported by syzbot involving af unix support of SO PEEK OFF. The issue arises because SO PEEK OFF is inherently not thread-safe, using a per-socket sk peek off field. After the patch, setsockopt(SO PEEK OFF) no longer acquires the socket lock, and skb consume udp() does not need to acquire the socket lock. Additionally, af unix no longer requires a special version of sk set peek off() since it does not lock u->iolock anymore.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the patch for this vulnerability. Specifically, versions 6.8.0-rc4-syzkaller-00267-g0f1dd5e91e2b and later should be used. If updating is not immediately possible, consider temporarily disabling the use of SO PEEK OFF to minimize the risk of exploitation.

Exploit

Fix

Improper Locking

Weakness Enumeration

Related Identifiers

BDU:2025-04397
CVE-2024-26732

Affected Products

Linux Kernel