Review reviewHigh

CVE-2024-26689

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This implies before the refcount could be increment here, it was freed. In same file, in "handle_cap_grant()" refcount is decremented by this line - 'ceph_buffer_put(ci->i_xattrs.blob);'. It appears that a race occurred and resource was freed by the latter line before the former line could increment it. encode_cap_msg() is called by __send_cap(...

CVSS
7.8
EPSS
0.70%
49.5% percentile
CISA KEV
Not listed
Published
2024.04.04
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.70%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This implies before the refcount could be increment here, it was freed. In same file, in "handle_cap_grant()" refcount is decremented by this line - 'ceph_buffer_put(ci->i_xattrs.blob);'. It appears that a race occurred and resource was freed by the latter line before the former line could increment it. encode_cap_msg() is called by __send_cap(...

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 9030aaf9bf0a1eee47a154c316c789e959638b0f < 8180d0c27b93a6eb60da1b08ea079e3926328214, >= 9030aaf9bf0a1eee47a154c316c789e959638b0f < 70e329b440762390258a6fe8c0de93c9fdd56c77, >= 9030aaf9bf0a1eee47a154c316c789e959638b0f < f3f98d7d84b31828004545e29fd7262b9f444139, >= 9030aaf9bf0a1eee47a154c316c789e959638b0f < ae20db45e482303a20e56f2db667a9d9c54ac7e7, >= 9030aaf9bf0a1eee47a154c316c789e959638b0f < 7958c1bf5b03c6f1f58e724dbdec93f8f60b96fc, >= 9030aaf9bf0a1eee47a154c316c789e959638b0f < cda4672da1c26835dcbd7aec2bfed954eda9b5ef, >= 2.6.34, < 5.10.210, >= 5.11 < 5.15.149, >= 5.16 < 6.1.79, >= 6.2 < 6.6.18, >= 6.7 < 6.7.6, 6.8, 10.0
Fixed versions
5.10.210, 5.15.149, 6.1.79, 6.6.18, 6.7.6

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416
CVE-2024-26689 — Linux Linux, linux kernel, debian linux | SECUFOCUS NOW