{ "dataType": "CVE_RECORD", "cveMetadata": { "cveId": "CVE-2024-36009", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-05-17T13:50:33.152Z", "datePublished": "2024-05-20T09:48:08.238Z", "dateUpdated": "2026-08-05T11:31:33.867Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:31:33.867Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Fix netdev refcount issue\n\nThe dev_tracker is added to ax25_cb in ax25_bind(). When the\nax25 device is detaching, the dev_tracker of ax25_cb should be\ndeallocated in ax25_kill_by_device() instead of the dev_tracker\nof ax25_dev. The log reported by ref_tracker is shown below:\n\n[ 80.884935] ref_tracker: reference already released.\n[ 80.885150] ref_tracker: allocated in:\n[ 80.885349] ax25_dev_device_up+0x105/0x540\n[ 80.885730] ax25_device_event+0xa4/0x420\n[ 80.885730] notifier_call_chain+0xc9/0x1e0\n[ 80.885730] __dev_notify_flags+0x138/0x280\n[ 80.885730] dev_change_flags+0xd7/0x180\n[ 80.885730] dev_ifsioc+0x6a9/0xa30\n[ 80.885730] dev_ioctl+0x4d8/0xd90\n[ 80.885730] sock_do_ioctl+0x1c2/0x2d0\n[ 80.885730] sock_ioctl+0x38b/0x4f0\n[ 80.885730] __se_sys_ioctl+0xad/0xf0\n[ 80.885730] do_syscall_64+0xc4/0x1b0\n[ 80.885730] entry_SYSCALL_64_after_hwframe+0x67/0x6f\n[ 80.885730] ref_tracker: freed in:\n[ 80.885730] ax25_device_event+0x272/0x420\n[ 80.885730] notifier_call_chain+0xc9/0x1e0\n[ 80.885730] dev_close_many+0x272/0x370\n[ 80.885730] unregister_netdevice_many_notify+0x3b5/0x1180\n[ 80.885730] unregister_netdev+0xcf/0x120\n[ 80.885730] sixpack_close+0x11f/0x1b0\n[ 80.885730] tty_ldisc_kill+0xcb/0x190\n[ 80.885730] tty_ldisc_hangup+0x338/0x3d0\n[ 80.885730] __tty_hangup+0x504/0x740\n[ 80.885730] tty_release+0x46e/0xd80\n[ 80.885730] __fput+0x37f/0x770\n[ 80.885730] __x64_sys_close+0x7b/0xb0\n[ 80.885730] do_syscall_64+0xc4/0x1b0\n[ 80.885730] entry_SYSCALL_64_after_hwframe+0x67/0x6f\n[ 80.893739] ------------[ cut here ]------------\n[ 80.894030] WARNING: CPU: 2 PID: 140 at lib/ref_tracker.c:255 ref_tracker_free+0x47b/0x6b0\n[ 80.894297] Modules linked in:\n[ 80.894929] CPU: 2 PID: 140 Comm: ax25_conn_rel_6 Not tainted 6.9.0-rc4-g8cd26fd90c1a #11\n[ 80.895190] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qem4\n[ 80.895514] RIP: 0010:ref_tracker_free+0x47b/0x6b0\n[ 80.895808] Code: 83 c5 18 4c 89 eb 48 c1 eb 03 8a 04 13 84 c0 0f 85 df 01 00 00 41 83 7d 00 00 75 4b 4c 89 ff 9\n[ 80.896171] RSP: 0018:ffff888009edf8c0 EFLAGS: 00000286\n[ 80.896339] RAX: 1ffff1100141ac00 RBX: 1ffff1100149463b RCX: dffffc0000000000\n[ 80.896502] RDX: 0000000000000001 RSI: 0000000000000246 RDI: ffff88800a0d6518\n[ 80.896925] RBP: ffff888009edf9b0 R08: ffff88806d3288d3 R09: 1ffff1100da6511a\n[ 80.897212] R10: dffffc0000000000 R11: ffffed100da6511b R12: ffff88800a4a31d4\n[ 80.897859] R13: ffff88800a4a31d8 R14: dffffc0000000000 R15: ffff88800a0d6518\n[ 80.898279] FS: 00007fd88b7fe700(0000) GS:ffff88806d300000(0000) knlGS:0000000000000000\n[ 80.899436] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 80.900181] CR2: 00007fd88c001d48 CR3: 000000000993e000 CR4: 00000000000006f0\n...\n[ 80.935774] ref_tracker: sp%d@000000000bb9df3d has 1/1 users at\n[ 80.935774] ax25_bind+0x424/0x4e0\n[ 80.935774] __sys_bind+0x1d9/0x270\n[ 80.935774] __x64_sys_bind+0x75/0x80\n[ 80.935774] do_syscall_64+0xc4/0x1b0\n[ 80.935774] entry_SYSCALL_64_after_hwframe+0x67/0x6f\n\nChange ax25_dev->dev_tracker to the dev_tracker of ax25_cb\nin order to mitigate the bug." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerable path is reached through local syscalls — socket()/bind() on AF_AX25 plus the netdev down/unregister notifier — and AX.25 sockets and devices are restricted to the initial network namespace, so no remote or adjacent packet path reaches this code.\nAC:L - Within an affected configuration the erroneous tracker release is deterministic: any socket bound to the AX.25 device makes ax25_kill_by_device() free the wrong tracker, and the subsequent ax25_dev_device_down() double-free is unconditional. The heap-recycling escalation is driven by attacker-controlled AX.25 bind/close churn on both sides, so no condition outside the attacker's influence is required.\nPR:L - An ordinary unprivileged local user can create and bind an AX.25 socket (ax25_create requires no capability for SOCK_SEQPACKET/SOCK_DGRAM and ax25_bind only checks CAP_NET_ADMIN when the non-default ax25_uid_policy is set), and that bound socket is the precondition that makes the buggy netdev_put() execute.\nUI:N - No victim action is needed for the exploit itself — the trigger is the interface going down or the KISS/6pack TNC detaching, which happens as routine operation of an AX.25 station rather than as a deliberate user action on the attacker's behalf.\nS:U - The mismanaged reference tracking, the WARN, and any resulting memory corruption all occur inside the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The stale ax25_dev->dev_tracker pointer is dereferenced after the tracker object is recycled out of the 128-entry quarantine, giving a read of freed/reused slab memory whose contents the attacker can groom, which is an arbitrary-read style disclosure primitive; the WARN/ref_tracker splats additionally dump kernel addresses and stack traces.\nI:H - After the tracker is freed, ref_tracker_free() writes tracker->free_stack_handle and performs list_move_tail() on the reused object, yielding a list-unlink write with attacker-influenced pointers — memory corruption exploitable for control-flow hijacking.\nA:H - The bug reliably produces a WARNING at lib/ref_tracker.c:255 (a panic on panic_on_warn systems) plus a second WARN for leaked trackers at netdev teardown, and the freed-object path causes kernel oopses/heap corruption; the unreleased ax25_cb trackers also leak memory for the netdev's lifetime." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/ax25/af_ax25.c" ], "versions": [ { "version": "feef318c855a361a1eccd880f33e88c460eb63b4", "lessThan": "0d14f104027e30720582448706c7d6b43065c851", "status": "affected", "versionType": "git" }, { "version": "feef318c855a361a1eccd880f33e88c460eb63b4", "lessThan": "4fee8fa86a15d7790268eea458b1aec69c695530", "status": "affected", "versionType": "git" }, { "version": "feef318c855a361a1eccd880f33e88c460eb63b4", "lessThan": "c42b073d9af4a5329b25b17390c63ab3847f30e8", "status": "affected", "versionType": "git" }, { "version": "feef318c855a361a1eccd880f33e88c460eb63b4", "lessThan": "467324bcfe1a31ec65d0cf4aa59421d6b7a7d52b", "status": "affected", "versionType": "git" }, { "version": "b8c07f33aa35dacf5444e7053ed9662d1869f536", "status": "affected", "versionType": "git" }, { "version": "b1e0a6fc7f17500484c402ad1cd018c24dfc14b3", "status": "affected", "versionType": "git" }, { "version": "7528d0f2210c3a1154186175516ed37aa970f2b1", "status": "affected", "versionType": "git" }, { "version": "57cc15f5fd550316e4104eaf84b90fbc640fd7a5", "status": "affected", "versionType": "git" }, { "version": "b982492ec3a115e0a136856a1b2dbe32f2d21a0e", "status": "affected", "versionType": "git" }, { "version": "4.14.277", "lessThan": "4.15", "status": "affected", "versionType": "semver" }, { "version": "4.19.240", "lessThan": "4.20", "status": "affected", "versionType": "semver" }, { "version": "5.4.190", "lessThan": "5.5", "status": "affected", "versionType": "semver" }, { "version": "5.10.112", "lessThan": "5.11", "status": "affected", "versionType": "semver" }, { "version": "5.15.35", "lessThan": "5.16", "status": "affected", "versionType": "semver" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/ax25/af_ax25.c" ], "versions": [ { "version": "5.17", "status": "affected" }, { "version": "0", "lessThan": "5.17", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.90", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.30", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.8.9", "lessThanOrEqual": "6.8.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.9", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.17", "versionEndExcluding": "6.1.90" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.17", "versionEndExcluding": "6.6.30" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.17", "versionEndExcluding": "6.8.9" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.17", "versionEndExcluding": "6.9" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.14.277" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.19.240" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.4.190" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.10.112" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.15.35" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/0d14f104027e30720582448706c7d6b43065c851" }, { "url": "https://git.kernel.org/stable/c/4fee8fa86a15d7790268eea458b1aec69c695530" }, { "url": "https://git.kernel.org/stable/c/c42b073d9af4a5329b25b17390c63ab3847f30e8" }, { "url": "https://git.kernel.org/stable/c/467324bcfe1a31ec65d0cf4aa59421d6b7a7d52b" } ], "title": "ax25: Fix netdev refcount issue", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-06-13T20:06:19.404612Z", "id": "CVE-2024-36009", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-06-13T20:06:29.490Z" } }, { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T03:30:12.796Z" }, "title": "CVE Program Container", "references": [ { "url": "https://git.kernel.org/stable/c/0d14f104027e30720582448706c7d6b43065c851", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/4fee8fa86a15d7790268eea458b1aec69c695530", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/c42b073d9af4a5329b25b17390c63ab3847f30e8", "tags": [ "x_transferred" ] }, { "url": "https://git.kernel.org/stable/c/467324bcfe1a31ec65d0cf4aa59421d6b7a7d52b", "tags": [ "x_transferred" ] }, { "url": "http://www.openwall.com/lists/oss-security/2024/05/30/2", "tags": [ "x_transferred" ] }, { "url": "http://www.openwall.com/lists/oss-security/2024/05/30/1", "tags": [ "x_transferred" ] } ] } ] }, "dataVersion": "5.2" }