In the Linux kernel, the following vulnerability has been resolved:
net: openvswitch: Fix Use-After-Free in ovsctexit
Since kfreercu, which is called in the hlistforeachentryrcu traversal of ovsctlimitexit, is not part of the RCU read critical section, it is possible that the RCU grace period will pass during the traversal and the key will be free.
To prevent this, it should be changed to hlistforeachentrysafe.
[
{
"digest": {
"function_hash": "98433200627444720242250803086982063981",
"length": 431.0
},
"target": {
"file": "net/openvswitch/conntrack.c",
"function": "ovs_ct_limit_exit"
},
"id": "CVE-2024-27395-2a430e8e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9048616553c65e750d43846f225843ed745ec0d4",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"105958704098206579920866900077741353403",
"123448609476980054900961567629080894159",
"188777577576517097218846479077024799224",
"251844365132412756684755411151188407998",
"7731318501552698090745741836238018247",
"137227940387818603395845067345713690887"
],
"threshold": 0.9
},
"target": {
"file": "net/openvswitch/conntrack.c"
},
"id": "CVE-2024-27395-48e7a710",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5ea7b72d4fac2fdbc0425cd8f2ea33abe95235b2",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"105958704098206579920866900077741353403",
"123448609476980054900961567629080894159",
"188777577576517097218846479077024799224",
"251844365132412756684755411151188407998",
"7731318501552698090745741836238018247",
"329483938898814446310710809265867627529"
],
"threshold": 0.9
},
"target": {
"file": "net/openvswitch/conntrack.c"
},
"id": "CVE-2024-27395-4f0d38dc",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2db9a8c0a01fa1c762c1e61a13c212c492752994",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"105958704098206579920866900077741353403",
"123448609476980054900961567629080894159",
"188777577576517097218846479077024799224",
"251844365132412756684755411151188407998",
"7731318501552698090745741836238018247",
"137227940387818603395845067345713690887"
],
"threshold": 0.9
},
"target": {
"file": "net/openvswitch/conntrack.c"
},
"id": "CVE-2024-27395-5162d0bf",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@35880c3fa6f8fe281a19975d2992644588ca33d3",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"105958704098206579920866900077741353403",
"123448609476980054900961567629080894159",
"188777577576517097218846479077024799224",
"251844365132412756684755411151188407998",
"7731318501552698090745741836238018247",
"137227940387818603395845067345713690887"
],
"threshold": 0.9
},
"target": {
"file": "net/openvswitch/conntrack.c"
},
"id": "CVE-2024-27395-6b09c406",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eaa5e164a2110d2fb9e16c8a29e4501882235137",
"deprecated": false
},
{
"digest": {
"function_hash": "98433200627444720242250803086982063981",
"length": 431.0
},
"target": {
"file": "net/openvswitch/conntrack.c",
"function": "ovs_ct_limit_exit"
},
"id": "CVE-2024-27395-6c87856d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@eaa5e164a2110d2fb9e16c8a29e4501882235137",
"deprecated": false
},
{
"digest": {
"function_hash": "327662740551272144871373927700422000676",
"length": 469.0
},
"target": {
"file": "net/openvswitch/conntrack.c",
"function": "ovs_ct_limit_exit"
},
"id": "CVE-2024-27395-7d19dd44",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2db9a8c0a01fa1c762c1e61a13c212c492752994",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"105958704098206579920866900077741353403",
"123448609476980054900961567629080894159",
"188777577576517097218846479077024799224",
"251844365132412756684755411151188407998",
"7731318501552698090745741836238018247",
"137227940387818603395845067345713690887"
],
"threshold": 0.9
},
"target": {
"file": "net/openvswitch/conntrack.c"
},
"id": "CVE-2024-27395-842ac035",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@edee0758747d7c219e29db9ed1d4eb33e8d32865",
"deprecated": false
},
{
"digest": {
"function_hash": "327662740551272144871373927700422000676",
"length": 469.0
},
"target": {
"file": "net/openvswitch/conntrack.c",
"function": "ovs_ct_limit_exit"
},
"id": "CVE-2024-27395-84582664",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@589523cf0b384164e445dd5db8d5b1bf97982424",
"deprecated": false
},
{
"digest": {
"function_hash": "98433200627444720242250803086982063981",
"length": 431.0
},
"target": {
"file": "net/openvswitch/conntrack.c",
"function": "ovs_ct_limit_exit"
},
"id": "CVE-2024-27395-8cb98fd7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@edee0758747d7c219e29db9ed1d4eb33e8d32865",
"deprecated": false
},
{
"digest": {
"function_hash": "98433200627444720242250803086982063981",
"length": 431.0
},
"target": {
"file": "net/openvswitch/conntrack.c",
"function": "ovs_ct_limit_exit"
},
"id": "CVE-2024-27395-9494e6f0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bca6fa2d9a9f560e6b89fd5190b05cc2f5d422c1",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"105958704098206579920866900077741353403",
"123448609476980054900961567629080894159",
"188777577576517097218846479077024799224",
"251844365132412756684755411151188407998",
"7731318501552698090745741836238018247",
"137227940387818603395845067345713690887"
],
"threshold": 0.9
},
"target": {
"file": "net/openvswitch/conntrack.c"
},
"id": "CVE-2024-27395-b3c3d518",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bca6fa2d9a9f560e6b89fd5190b05cc2f5d422c1",
"deprecated": false
},
{
"digest": {
"function_hash": "98433200627444720242250803086982063981",
"length": 431.0
},
"target": {
"file": "net/openvswitch/conntrack.c",
"function": "ovs_ct_limit_exit"
},
"id": "CVE-2024-27395-dc884459",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@35880c3fa6f8fe281a19975d2992644588ca33d3",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"105958704098206579920866900077741353403",
"123448609476980054900961567629080894159",
"188777577576517097218846479077024799224",
"251844365132412756684755411151188407998",
"7731318501552698090745741836238018247",
"137227940387818603395845067345713690887"
],
"threshold": 0.9
},
"target": {
"file": "net/openvswitch/conntrack.c"
},
"id": "CVE-2024-27395-faf8bb44",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9048616553c65e750d43846f225843ed745ec0d4",
"deprecated": false
},
{
"digest": {
"function_hash": "98433200627444720242250803086982063981",
"length": 431.0
},
"target": {
"file": "net/openvswitch/conntrack.c",
"function": "ovs_ct_limit_exit"
},
"id": "CVE-2024-27395-fe23cfc8",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5ea7b72d4fac2fdbc0425cd8f2ea33abe95235b2",
"deprecated": false
},
{
"digest": {
"line_hashes": [
"105958704098206579920866900077741353403",
"123448609476980054900961567629080894159",
"188777577576517097218846479077024799224",
"251844365132412756684755411151188407998",
"7731318501552698090745741836238018247",
"329483938898814446310710809265867627529"
],
"threshold": 0.9
},
"target": {
"file": "net/openvswitch/conntrack.c"
},
"id": "CVE-2024-27395-ffd7bef0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@589523cf0b384164e445dd5db8d5b1bf97982424",
"deprecated": false
}
]