CVE-2023-52999

Source
https://cve.org/CVERecord?id=CVE-2023-52999
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52999.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-52999
Downstream
Related
Published
2025-03-27T16:43:32.497Z
Modified
2026-03-20T12:32:54.354353Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: fix UaF in netns ops registration error path
Details

In the Linux kernel, the following vulnerability has been resolved:

net: fix UaF in netns ops registration error path

If netassigngeneric() fails, the current error path in ops_init() tries to clear the gen pointer slot. Anyway, in such error path, the gen pointer itself has not been modified yet, and the existing and accessed one is smaller than the accessed index, causing an out-of-bounds error:

BUG: KASAN: slab-out-of-bounds in ops_init+0x2de/0x320 Write of size 8 at addr ffff888109124978 by task modprobe/1018

CPU: 2 PID: 1018 Comm: modprobe Not tainted 6.2.0-rc2.mptcpae5ac65fbed5+ #1641 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.1-2.fc37 04/01/2014 Call Trace: <TASK> dumpstacklvl+0x6a/0x9f printaddressdescription.constprop.0+0x86/0x2b5 printreport+0x11b/0x1fb kasanreport+0x87/0xc0 opsinit+0x2de/0x320 registerpernetoperations+0x2e4/0x750 registerpernetsubsys+0x24/0x40 tcfregisteraction+0x9f/0x560 dooneinitcall+0xf9/0x570 doinitmodule+0x190/0x650 load_module+0x1fa5/0x23c0 __dosysfinitmodule+0x10d/0x1b0 dosyscall64+0x58/0x80 entrySYSCALL64afterhwframe+0x72/0xdc RIP: 0033:0x7f42518f778d Code: 00 c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d cb 56 2c 00 f7 d8 64 89 01 48 RSP: 002b:00007fff96869688 EFLAGS: 00000246 ORIGRAX: 0000000000000139 RAX: ffffffffffffffda RBX: 00005568ef7f7c90 RCX: 00007f42518f778d RDX: 0000000000000000 RSI: 00005568ef41d796 RDI: 0000000000000003 RBP: 00005568ef41d796 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000003 R11: 0000000000000246 R12: 0000000000000000 R13: 00005568ef7f7d30 R14: 0000000000040000 R15: 0000000000000000 </TASK>

This change addresses the issue by skipping the gen pointer de-reference in the mentioned error-path.

Found by code inspection and verified with explicit error injection on a kasan-enabled kernel.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/52xxx/CVE-2023-52999.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5a2ea549be94924364f6911227d99be86e8cf34a
Fixed
ad0dfe9bcf0d78e699c7efb64c90ed062dc48bea
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
97ad240fd9aa9214497d14af2b91608e20856cac
Fixed
ddd49cbbd4c1ceb38032018b589b44208e54f55e
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c3edc6e808209aa705185f732e682a370981ced1
Fixed
d4c008f3b7f7d4ffd311eb2dae5e75b3cbddacd0
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a1e18acb0246bfb001b08b8b1b830b5ec92a0f13
Fixed
66689a72ba73575e76d4f6a8748d3fa2690ec1c4
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
d266935ac43d57586e311a087510fe6a084af742
Fixed
12075708f2e77ee6a9f8bb2cf512c38be3099794
Fixed
71ab9c3e2253619136c31c89dbb2c69305cc89b1
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
4a4df5e78712de39d6f90d6a64b5eb48dca03bd5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-52999.json"