CVE-2024-35934

Siemens ProductCERT Advisory SSA-265688

Beschreibung

Im Linux-Kernel wurde folgende Schwachstelle behoben: `net/smc`: Reduziere den Druck auf `rtnl` in `smc_pnet_create_pnetids_list()`. Viele Berichte von syzbot zeigen extremen Druck auf `rtnl`, und viele davon deuten darauf hin, dass smc `rtnl` im Netzwerknamespace (NetNS) erstellen ohne triftigen Grund erlangt [1]. Dieser Patch kehrt frühzeitig aus `smc_pnet_net_init()` zurück, wenn es noch kein Netzgerät gibt. Ich bin mir nicht einmal sicher, warum `smc_pnet_create_pnetids_list()` überhaupt existiert, da `smc_pnet_netdev_event()` auch `smc_pnet_add_base_pnetid()` aufruft, wenn ein NETDEV_UP-Ereignis behandelt wird. [1] Auszug aus typischen syzbot-Berichten 2 Sperren gehalten von syz-executor.3/12252: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878 2 Sperren gehalten von syz-executor.4/12253: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878 2 Sperren gehalten von syz-executor.1/12257: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878 2 Sperren gehalten von syz-executor.2/12261: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878 2 Sperren gehalten von syz-executor.0/12265: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878 2 Sperren gehalten von syz-executor.3/12268: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878 2 Sperren gehalten von syz-executor.4/12271: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878 2 Sperren gehalten von syz-executor.1/12274: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878 2 Sperren gehalten von syz-executor.2/12280: #0: ffffffff8f369610 (pernet_ops_rwsem){++++}-{3:3}, bei: copy_net_ns+0x4c7/0x7b0 net/core/net_namespace.c:491 #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_create_pnetids_list net/smc/smc_pnet.c:809 [inline] #1: ffffffff8f375b88 (rtnl_mutex){+.+.}-{3:3}, bei: smc_pnet_net_init+0x10a/0x1e0 net/smc/smc_pnet.c:878

Metriken

Severity
none
kein öffentlicher PoC bekannt
11.5 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2022-02-18 00:00 UTC

Betroffene Betriebssysteme

  • linux

    amazon / amazon_linux

  • linux

    suse / basesystem_module15

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux12.0

  • linux

    debian / debian_linux13.0

  • linux

    suse / development_tools_module15

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_aus8.4

  • linux

    redhat / enterprise_linux_aus8.6

  • linux

    redhat / enterprise_linux_eus10.0

  • linux

    redhat / enterprise_linux_eus8.4

  • linux

    redhat / enterprise_linux_eus9.4

  • linux

    redhat / enterprise_linux_eus9.6

  • linux

    redhat / enterprise_linux_tus8.6

  • linux

    redhat / enterprise_linux_tus8.8

  • linux

    redhat / enterprise_linux_update_services_for_sap_solutions8.6

  • linux

    redhat / enterprise_linux_update_services_for_sap_solutions8.8

  • linux

    redhat / enterprise_linux_update_services_for_sap_solutions9.0

  • linux

    redhat / enterprise_linux_update_services_for_sap_solutions9.2

  • linux

    opensuse / leap15.3

  • linux

    opensuse / leap15.4

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • android

    :linux_kernel::0

  • android

    :linux_kernel:Kernel

  • arista

    cloudvision_agni2024.4.0 – 2025.2.2

  • arista

    cloudvision_portal2024.2.0 – 2026.1.0

  • arista

    velocloud_edge4.5.0 – 6.4.1

  • arista

    velocloud_gateway

  • arista

    velocloud_orchestrator

  • bitnami

    java-min1.9.0

  • Dell

    ECS3.8.1.0

  • Dell

    NetWorkerVirtual Edition

  • Dell

    NetWorkervProxy

  • Dell

    PowerProtect Data Domain7.10.1.70

  • Dell

    PowerProtect Data Domain7.13.1.40

  • Dell

    PowerProtect Data Domain8.3.1.10

  • Dell

    PowerProtect Data Domain8.4.0.0

  • Dell

    PowerProtect Data Domain< 7.10.1.70

    gefixt in 7.10.1.70

  • Dell

    PowerProtect Data Domain< 7.13.1.40

    gefixt in 7.13.1.40

  • Dell

    PowerProtect Data Domain< 8.3.1.10

    gefixt in 8.3.1.10

  • Dell

    PowerProtect Data Domain< 8.4.0.0

    gefixt in 8.4.0.0

  • Dell

    PowerScale OneFSNode Firmware Package 14.1

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • Hitachi Energy

    RTU500< 13.9.1

    gefixt in 13.9.1

  • HPE

    HP-UXOpenSSL Software <A.03.00.15.001

  • IBM

    AIX7.2

Quellen & Referenzen

Verknüpfte CVEs

423 weitere CVEs anzeigen
IDCVE-2024-35934
Siemens ProductCERT Advisory SSA-265688 — CVE-2024-35934 | NEOSEC Intel