{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-47695", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-09-30T16:00:12.942Z", "datePublished": "2024-10-21T11:53:33.266Z", "dateUpdated": "2026-08-05T11:39:28.289Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:39:28.289Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds\n\nIn the function init_conns(), after the create_con() and create_cm() for\nloop if something fails. In the cleanup for loop after the destroy tag, we\naccess out of bound memory because cid is set to clt_path->s.con_num.\n\nThis commits resets the cid to clt_path->s.con_num - 1, to stay in bounds\nin the cleanup loop later." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL" }, "scenarios": [ { "lang": "en", "value": "AV:N - The failure that reaches the out-of-bounds cleanup loop is induced entirely by the remote RTRS server's `max_hdr_size` field in the RDMA-CM connect-response private data, which flows unvalidated into the `kzalloc()` in `rtrs_iu_alloc()`. RTRS/RNBD runs over RoCEv2 and iWARP, which are IP-routable, so the peer need not be link-local.\nAC:L - The attacker directly controls the exact field (`max_hdr_size`) that makes `alloc_path_reqs()` fail, so the OOB is reached deterministically with no race and no uncontrolled precondition. With `MAX_RECONNECTS = -1` the server can force the reconnect path indefinitely, allowing repeated attempts and heap grooming of the adjacent slab slot.\nPR:N - The rtrs connection handshake performs only a magic/version/errno check and has no authentication whatsoever, so any host able to answer the client's connect request is implicitly trusted. The attacker holds no credentials or privileges on the victim machine.\nUI:N - Once an rnbd/rtrs session exists as part of normal storage operation, the server simply drops the link and `rtrs_clt_reconnect_work()` re-enters `init_path()` -> `init_conns()` automatically after the reconnect delay. No administrator or user action is required at exploit time.\nS:U - The out-of-bounds read and the subsequent wild-pointer dereferences and free all occur within kernel memory managed by the same security authority. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - `s.con[con_num]` reads uninitialized slab memory past the `kcalloc()`ed array, and that stale value is then dereferenced as a `struct rtrs_clt_con *` through `con->c.cm_id`, `con->c.qp`, `con->c.path`, and `con->rsp_ius`. Combined with the arbitrary-free primitive and the attacker's ability to groom the neighbouring heap slot across repeated reconnects, this is leverageable into kernel memory disclosure.\nI:H - `destroy_con()` performs `clt_path->s.con[con->c.cid] = NULL` using a wild base pointer and a wild 32-bit index (a semi-arbitrary NULL write) and then `kfree(con)` on the stale pointer, and `destroy_con_cq_qp()` writes through `con->c.path` as well. Arbitrary free plus controlled heap corruption is the standard route to control-flow hijack.\nA:H - Even without any grooming, treating stale slab data as a `struct rtrs_clt_con *` and calling `rdma_disconnect()`/`ib_drain_qp()`/`rdma_destroy_id()`/`kfree()` on it reliably oopses or panics the kernel. The remote server can retrigger this on every reconnect cycle indefinitely, taking down the storage client host." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/infiniband/ulp/rtrs/rtrs-clt.c" ], "versions": [ { "version": "6a98d71daea186247005099758af549e6afdd244", "lessThan": "0429a4e972082e3a2351da414b1c017daaf8aed2", "status": "affected", "versionType": "git" }, { "version": "6a98d71daea186247005099758af549e6afdd244", "lessThan": "5ac73f8191f3de41fef4f934d84d97f3aadb301f", "status": "affected", "versionType": "git" }, { "version": "6a98d71daea186247005099758af549e6afdd244", "lessThan": "01b9be936ee8839ab9f83a7e84ee02ac6c8303c4", "status": "affected", "versionType": "git" }, { "version": "6a98d71daea186247005099758af549e6afdd244", "lessThan": "1c50e0265fa332c94a4a182e4efa0fc70d8fad94", "status": "affected", "versionType": "git" }, { "version": "6a98d71daea186247005099758af549e6afdd244", "lessThan": "c8b7f3d9fada0d4b4b7db86bf7345cd61f1d972e", "status": "affected", "versionType": "git" }, { "version": "6a98d71daea186247005099758af549e6afdd244", "lessThan": "3e4289b29e216a55d08a89e126bc0b37cbad9f38", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/infiniband/ulp/rtrs/rtrs-clt.c" ], "versions": [ { "version": "5.8", "status": "affected" }, { "version": "0", "lessThan": "5.8", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.168", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.113", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.54", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.10.13", "lessThanOrEqual": "6.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.11.2", "lessThanOrEqual": "6.11.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.8", "versionEndExcluding": "5.15.168" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.8", "versionEndExcluding": "6.1.113" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.8", "versionEndExcluding": "6.6.54" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.8", "versionEndExcluding": "6.10.13" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.8", "versionEndExcluding": "6.11.2" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.8", "versionEndExcluding": "6.12" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/0429a4e972082e3a2351da414b1c017daaf8aed2" }, { "url": "https://git.kernel.org/stable/c/5ac73f8191f3de41fef4f934d84d97f3aadb301f" }, { "url": "https://git.kernel.org/stable/c/01b9be936ee8839ab9f83a7e84ee02ac6c8303c4" }, { "url": "https://git.kernel.org/stable/c/1c50e0265fa332c94a4a182e4efa0fc70d8fad94" }, { "url": "https://git.kernel.org/stable/c/c8b7f3d9fada0d4b4b7db86bf7345cd61f1d972e" }, { "url": "https://git.kernel.org/stable/c/3e4289b29e216a55d08a89e126bc0b37cbad9f38" } ], "title": "RDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "id": "CVE-2024-47695", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2024-10-21T13:05:20.037863Z" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-10-21T13:14:14.534Z" } }, { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T22:20:59.878Z" } } ] } }