{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-45013", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-08-21T05:34:56.681Z", "datePublished": "2024-09-11T15:13:50.210Z", "dateUpdated": "2026-08-05T11:37:40.579Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:37:40.579Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: move stopping keep-alive into nvme_uninit_ctrl()\n\nCommit 4733b65d82bd (\"nvme: start keep-alive after admin queue setup\")\nmoves starting keep-alive from nvme_start_ctrl() into\nnvme_init_ctrl_finish(), but don't move stopping keep-alive into\nnvme_uninit_ctrl(), so keep-alive work can be started and keep pending\nafter failing to start controller, finally use-after-free is triggered if\nnvme host driver is unloaded.\n\nThis patch fixes kernel panic when running nvme/004 in case that connection\nfailure is triggered, by moving stopping keep-alive into nvme_uninit_ctrl().\n\nThis way is reasonable because keep-alive is now started in\nnvme_init_ctrl_finish()." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL" }, "scenarios": [ { "lang": "en", "value": "AV:N - The affected code is the NVMe-over-Fabrics host driver (nvme-tcp/nvme-rdma), which is bound to the network stack and drives controller setup from responses supplied by a remote NVMe-oF target; a malicious, compromised, or spoofed target on the network fully controls whether setup fails after nvme_init_ctrl_finish() and when the keep-alive completion lands. NVMe/TCP has no mandatory authentication or encryption in typical deployments, so the attacker set extends to the network.\nAC:L - The remote target controls both sides of the interleaving — it chooses when to answer the keep-alive command and when to fail or stall the I/O-queue connect — and hosts retry connection setup automatically, giving unlimited attempts; the nvme-loop variant (loop.c:468-476, 573-618) has no race at all and leaks ka_work deterministically.\nPR:N - The attacker acts as the NVMe-oF target (or spoofs/MITMs the unauthenticated TCP connection) and needs no account, credentials, or privileges of any kind on the victim host. The vulnerable path runs during connection establishment, before any optional DH-HMAC-CHAP authentication is a factor.\nUI:N - Production NVMe-oF hosts connect automatically via nvmf-autoconnect at boot and via discovery-controller AEN-driven auto-connect (nvme-stas), so an attacker controlling the discovery/target endpoint can trigger repeated nvme_tcp_create_ctrl() attempts with no human action; the nvme-loop reset path (nvme_loop_reset_ctrl_work) is likewise entered automatically on controller error.\nS:U - The use-after-free occurs on kernel heap memory and is exploited within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The freed nvme_tcp_ctrl/nvme_loop_ctrl object can be reclaimed and re-sprayed by the attacker, and the stale timer/work dereference over that memory yields a controllable read and, once control flow is hijacked via work->func, arbitrary kernel memory disclosure.\nI:H - The armed delayed_work lives inside the kfree()d controller, so timer expiry calls timer->function and the worker calls work->func from freed heap; reallocating that slab object gives the attacker a kernel function pointer under their control, i.e. arbitrary code execution and unrestricted modification of kernel state.\nA:H - Even without successful exploitation the stale delayed work fires on freed memory and reliably panics the kernel — this is exactly the reported crash from blktests nvme/004 — which is a complete denial of service on the storage host." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/nvme/host/core.c" ], "versions": [ { "version": "3af755a46881c32fecaecfdeaf3a8f0a869deca5", "lessThan": "4101af98ab573554c4225e328d506fec2a74bc54", "status": "affected", "versionType": "git" }, { "version": "3af755a46881c32fecaecfdeaf3a8f0a869deca5", "lessThan": "a54a93d0e3599b05856971734e15418ac551a14c", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/nvme/host/core.c" ], "versions": [ { "version": "6.7", "status": "affected" }, { "version": "0", "lessThan": "6.7", "status": "unaffected", "versionType": "semver" }, { "version": "6.10.7", "lessThanOrEqual": "6.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.10.7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.7", "versionEndExcluding": "6.11" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/4101af98ab573554c4225e328d506fec2a74bc54" }, { "url": "https://git.kernel.org/stable/c/a54a93d0e3599b05856971734e15418ac551a14c" } ], "title": "nvme: move stopping keep-alive into nvme_uninit_ctrl()", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2024-09-29T15:50:07.552201Z", "id": "CVE-2024-45013", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-29T15:50:22.500Z" } } ] } }