CVE-2024-26638

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-26638
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-26638.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-26638
Downstream
Related
Published
2024-03-18T10:14:48Z
Modified
2025-10-14T12:47:51.961941Z
Severity
  • 4.4 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
nbd: always initialize struct msghdr completely
Details

In the Linux kernel, the following vulnerability has been resolved:

nbd: always initialize struct msghdr completely

syzbot complains that msg->msggetinq value can be uninitialized [1]

struct msghdr got many new fields recently, we should always make sure their values is zero by default.

[1] BUG: KMSAN: uninit-value in tcprecvmsg+0x686/0xac0 net/ipv4/tcp.c:2571 tcprecvmsg+0x686/0xac0 net/ipv4/tcp.c:2571 inetrecvmsg+0x131/0x580 net/ipv4/afinet.c:879 sockrecvmsgnosec net/socket.c:1044 [inline] sockrecvmsg+0x12b/0x1e0 net/socket.c:1066 _sockxmit+0x236/0x5c0 drivers/block/nbd.c:538 nbdreadreply drivers/block/nbd.c:732 [inline] recvwork+0x262/0x3100 drivers/block/nbd.c:863 processonework kernel/workqueue.c:2627 [inline] processscheduledworks+0x104e/0x1e70 kernel/workqueue.c:2700 workerthread+0xf45/0x1490 kernel/workqueue.c:2781 kthread+0x3ed/0x540 kernel/kthread.c:388 retfromfork+0x66/0x80 arch/x86/kernel/process.c:147 retfromforkasm+0x11/0x20 arch/x86/entry/entry_64.S:242

Local variable msg created at: _sockxmit+0x4c/0x5c0 drivers/block/nbd.c:513 nbdreadreply drivers/block/nbd.c:732 [inline] recv_work+0x262/0x3100 drivers/block/nbd.c:863

CPU: 1 PID: 7465 Comm: kworker/u5:1 Not tainted 6.7.0-rc7-syzkaller-00041-gf016f7547aee #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023 Workqueue: nbd5-recv recv_work

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f94fd25cb0aaf77fd7453f31c5d394a1a68ecf60
Fixed
d9c54763e5cdbbd3f81868597fe8aca3c96e6387
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f94fd25cb0aaf77fd7453f31c5d394a1a68ecf60
Fixed
1960f2b534da1e6c65fb96f9e98bda773495f406
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f94fd25cb0aaf77fd7453f31c5d394a1a68ecf60
Fixed
b0028f333420a65a53a63978522db680b37379dd
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f94fd25cb0aaf77fd7453f31c5d394a1a68ecf60
Fixed
78fbb92af27d0982634116c7a31065f24d092826

Affected versions

v5.*

v5.18
v5.18-rc5
v5.18-rc6
v5.18-rc7
v5.19
v5.19-rc1
v5.19-rc2
v5.19-rc3
v5.19-rc4
v5.19-rc5
v5.19-rc6
v5.19-rc7
v5.19-rc8

v6.*

v6.0
v6.0-rc1
v6.0-rc2
v6.0-rc3
v6.0-rc4
v6.0-rc5
v6.0-rc6
v6.0-rc7
v6.1
v6.1-rc1
v6.1-rc2
v6.1-rc3
v6.1-rc4
v6.1-rc5
v6.1-rc6
v6.1-rc7
v6.1-rc8
v6.1.1
v6.1.10
v6.1.11
v6.1.12
v6.1.13
v6.1.14
v6.1.15
v6.1.16
v6.1.17
v6.1.18
v6.1.19
v6.1.2
v6.1.20
v6.1.21
v6.1.22
v6.1.23
v6.1.24
v6.1.25
v6.1.26
v6.1.27
v6.1.28
v6.1.29
v6.1.3
v6.1.30
v6.1.31
v6.1.32
v6.1.33
v6.1.34
v6.1.35
v6.1.36
v6.1.37
v6.1.38
v6.1.39
v6.1.4
v6.1.40
v6.1.41
v6.1.42
v6.1.43
v6.1.44
v6.1.45
v6.1.46
v6.1.47
v6.1.48
v6.1.49
v6.1.5
v6.1.50
v6.1.51
v6.1.52
v6.1.53
v6.1.54
v6.1.55
v6.1.56
v6.1.57
v6.1.58
v6.1.59
v6.1.6
v6.1.60
v6.1.61
v6.1.62
v6.1.63
v6.1.64
v6.1.65
v6.1.66
v6.1.67
v6.1.68
v6.1.69
v6.1.7
v6.1.70
v6.1.71
v6.1.72
v6.1.73
v6.1.74
v6.1.75
v6.1.8
v6.1.9
v6.2
v6.2-rc1
v6.2-rc2
v6.2-rc3
v6.2-rc4
v6.2-rc5
v6.2-rc6
v6.2-rc7
v6.2-rc8
v6.3
v6.3-rc1
v6.3-rc2
v6.3-rc3
v6.3-rc4
v6.3-rc5
v6.3-rc6
v6.3-rc7
v6.4
v6.4-rc1
v6.4-rc2
v6.4-rc3
v6.4-rc4
v6.4-rc5
v6.4-rc6
v6.4-rc7
v6.5
v6.5-rc1
v6.5-rc2
v6.5-rc3
v6.5-rc4
v6.5-rc5
v6.5-rc6
v6.5-rc7
v6.6
v6.6-rc1
v6.6-rc2
v6.6-rc3
v6.6-rc4
v6.6-rc5
v6.6-rc6
v6.6-rc7
v6.6.1
v6.6.10
v6.6.11
v6.6.12
v6.6.13
v6.6.14
v6.6.2
v6.6.3
v6.6.4
v6.6.5
v6.6.6
v6.6.7
v6.6.8
v6.6.9
v6.7
v6.7-rc1
v6.7-rc2
v6.7-rc3
v6.7-rc4
v6.7-rc5
v6.7-rc6
v6.7-rc7
v6.7-rc8
v6.7.1
v6.7.2

Database specific

{
    "vanir_signatures": [
        {
            "signature_type": "Function",
            "target": {
                "file": "drivers/block/nbd.c",
                "function": "__sock_xmit"
            },
            "signature_version": "v1",
            "digest": {
                "length": 843.0,
                "function_hash": "127111094330557077426269738594781097095"
            },
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d9c54763e5cdbbd3f81868597fe8aca3c96e6387",
            "deprecated": false,
            "id": "CVE-2024-26638-53f8aa20"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "drivers/block/nbd.c",
                "function": "__sock_xmit"
            },
            "signature_version": "v1",
            "digest": {
                "length": 885.0,
                "function_hash": "260752224909796851271360545059343979863"
            },
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1960f2b534da1e6c65fb96f9e98bda773495f406",
            "deprecated": false,
            "id": "CVE-2024-26638-7fc05286"
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "drivers/block/nbd.c"
            },
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "53270969597173793261042203421524886920",
                    "340244257594861203912086009649971144717",
                    "46016536618787779205332480409887258410",
                    "326430951206264093354088788398036568138",
                    "298532151071420019530946249036016740083",
                    "125730847816707162484217513417941582838",
                    "123693172889426091606629958431364135505",
                    "245993348783721138282621533013681830311",
                    "305894966972545186588663690220562903108",
                    "16410481754945380189905508054116281182",
                    "133258763409015438362589366260953061480"
                ]
            },
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0028f333420a65a53a63978522db680b37379dd",
            "deprecated": false,
            "id": "CVE-2024-26638-9d5aa945"
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "drivers/block/nbd.c"
            },
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "53270969597173793261042203421524886920",
                    "340244257594861203912086009649971144717",
                    "46016536618787779205332480409887258410",
                    "326430951206264093354088788398036568138",
                    "298532151071420019530946249036016740083",
                    "125730847816707162484217513417941582838",
                    "123693172889426091606629958431364135505",
                    "245993348783721138282621533013681830311",
                    "305894966972545186588663690220562903108",
                    "16410481754945380189905508054116281182",
                    "133258763409015438362589366260953061480"
                ]
            },
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1960f2b534da1e6c65fb96f9e98bda773495f406",
            "deprecated": false,
            "id": "CVE-2024-26638-af761813"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "drivers/block/nbd.c",
                "function": "__sock_xmit"
            },
            "signature_version": "v1",
            "digest": {
                "length": 885.0,
                "function_hash": "260752224909796851271360545059343979863"
            },
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b0028f333420a65a53a63978522db680b37379dd",
            "deprecated": false,
            "id": "CVE-2024-26638-b7d3612f"
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "drivers/block/nbd.c"
            },
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "53270969597173793261042203421524886920",
                    "340244257594861203912086009649971144717",
                    "46016536618787779205332480409887258410",
                    "326430951206264093354088788398036568138",
                    "121882886380709108498909943193826247618",
                    "127939728620773780677636857301463625713",
                    "152056705207112753058403507421321083636",
                    "245993348783721138282621533013681830311",
                    "305894966972545186588663690220562903108",
                    "16410481754945380189905508054116281182",
                    "133258763409015438362589366260953061480"
                ]
            },
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d9c54763e5cdbbd3f81868597fe8aca3c96e6387",
            "deprecated": false,
            "id": "CVE-2024-26638-cacbd8a4"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "drivers/block/nbd.c",
                "function": "__sock_xmit"
            },
            "signature_version": "v1",
            "digest": {
                "length": 885.0,
                "function_hash": "260752224909796851271360545059343979863"
            },
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@78fbb92af27d0982634116c7a31065f24d092826",
            "deprecated": false,
            "id": "CVE-2024-26638-f78c1bc0"
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "drivers/block/nbd.c"
            },
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "53270969597173793261042203421524886920",
                    "340244257594861203912086009649971144717",
                    "46016536618787779205332480409887258410",
                    "326430951206264093354088788398036568138",
                    "298532151071420019530946249036016740083",
                    "125730847816707162484217513417941582838",
                    "123693172889426091606629958431364135505",
                    "245993348783721138282621533013681830311",
                    "305894966972545186588663690220562903108",
                    "16410481754945380189905508054116281182",
                    "133258763409015438362589366260953061480"
                ]
            },
            "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@78fbb92af27d0982634116c7a31065f24d092826",
            "deprecated": false,
            "id": "CVE-2024-26638-ff519f6b"
        }
    ]
}

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.19.0
Fixed
6.1.76
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.15
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.3