{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-35890","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-17T13:50:33.113Z","datePublished":"2024-05-19T08:34:46.085Z","dateUpdated":"2026-08-05T11:30:44.493Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:30:44.493Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngro: fix ownership transfer\n\nIf packets are GROed with fraglist they might be segmented later on and\ncontinue their journey in the stack. In skb_segment_list those skbs can\nbe reused as-is. This is an issue as their destructor was removed in\nskb_gro_receive_list but not the reference to their socket, and then\nthey can't be orphaned. Fix this by also removing the reference to the\nsocket.\n\nFor example this could be observed,\n\n  kernel BUG at include/linux/skbuff.h:3131!  (skb_orphan)\n  RIP: 0010:ip6_rcv_core+0x11bc/0x19a0\n  Call Trace:\n   ipv6_list_rcv+0x250/0x3f0\n   __netif_receive_skb_list_core+0x49d/0x8f0\n   netif_receive_skb_list_internal+0x634/0xd40\n   napi_complete_done+0x1d2/0x7d0\n   gro_cell_poll+0x118/0x1f0\n\nA similar construction is found in skb_gro_receive, apply the same\nchange there."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The skbs that carry a socket reference into GRO are locally generated (`destructor == sock_wfree`), since remotely received packets are already orphaned in `ip_rcv_core()`/`ip6_rcv_core()`; the attacker must therefore send UDP traffic from a local socket over a veth pair. No remote peer can supply the sk-owning skbs directly.\nAC:L - The attacker controls every precondition — creating the veth pair, enabling GRO/rx-gro-list in their own netns, and sending a UDP burst that GRO deterministically aggregates and the stack then re-segments. No race or unknowable memory state is required for the crash, and the socket free timing for the UAF is also attacker-controlled (send, then close).\nPR:L - An unprivileged user can obtain CAP_NET_ADMIN in a private netns via `unshare -Urn`, which is sufficient to create the veth pair and to run `ethtool -K` (gated only by `ns_capable(net->user_ns, CAP_NET_ADMIN)`); the triggering traffic is then an ordinary UDP send. The resulting panic/UAF affects the whole host, not just the namespace.\nUI:N - The entire sequence is driven by the attacker's own process — interface configuration and packet transmission — with no action from any other user or administrator.\nS:U - The corruption and the crash occur within the kernel's own security authority; no hypervisor, IOMMU, or other authority boundary is crossed even though the trigger originates inside a container/netns.\nC:H - The detached segments retain an unreferenced `struct sock *`, so after `sock_wfree()` releases the last `sk_wmem_alloc` charge the pointer dangles; subsequent reads of `skb->sk` (e.g. `sk_fullsock()`, `sk_validate_xmit_skb()`) read freed, sprayable slab memory, giving a use-after-free disclosure primitive.\nI:H - The same dangling `sk` is used for an indirect call (`sk->sk_validate_xmit_skb(sk, dev, skb)`) and for accounting updates on a reallocated object, so a heap-sprayed sock allocation yields control-flow hijack / write-into-freed-object primitives typical of a use-after-free.\nA:H - The documented and easily reproduced result is `BUG_ON(skb->sk)` in `skb_orphan()` reached from `ip6_rcv_core()` under NAPI/softirq context, which oopses in interrupt context and panics the machine; it can be re-triggered at will."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/gro.c","net/ipv4/udp_offload.c"],"versions":[{"version":"5e10da5385d20c4bae587bc2921e5fdd9655d5fc","lessThan":"d225b0ac96dc40d7e8ae2bc227eb2c56e130975f","status":"affected","versionType":"git"},{"version":"5e10da5385d20c4bae587bc2921e5fdd9655d5fc","lessThan":"2eeab8c47c3c0276e0746bc382f405c9a236a5ad","status":"affected","versionType":"git"},{"version":"5e10da5385d20c4bae587bc2921e5fdd9655d5fc","lessThan":"fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6","status":"affected","versionType":"git"},{"version":"5e10da5385d20c4bae587bc2921e5fdd9655d5fc","lessThan":"5b3b67f731296027cceb3efad881ae281213f86f","status":"affected","versionType":"git"},{"version":"5e10da5385d20c4bae587bc2921e5fdd9655d5fc","lessThan":"ed4cccef64c1d0d5b91e69f7a8a6697c3a865486","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/core/gro.c","net/ipv4/udp_offload.c"],"versions":[{"version":"5.15","status":"affected"},{"version":"0","lessThan":"5.15","status":"unaffected","versionType":"semver"},{"version":"5.15.154","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.85","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.26","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.8.5","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"5.15.154"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.1.85"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.6.26"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.8.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d225b0ac96dc40d7e8ae2bc227eb2c56e130975f"},{"url":"https://git.kernel.org/stable/c/2eeab8c47c3c0276e0746bc382f405c9a236a5ad"},{"url":"https://git.kernel.org/stable/c/fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6"},{"url":"https://git.kernel.org/stable/c/5b3b67f731296027cceb3efad881ae281213f86f"},{"url":"https://git.kernel.org/stable/c/ed4cccef64c1d0d5b91e69f7a8a6697c3a865486"}],"title":"gro: fix ownership transfer","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-35890","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-05-23T17:20:18.616682Z"}}}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:33:50.532Z"}},{"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/d225b0ac96dc40d7e8ae2bc227eb2c56e130975f","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/2eeab8c47c3c0276e0746bc382f405c9a236a5ad","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/fc126c1d51e9552eacd2d717b9ffe9262a8a4cd6","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/5b3b67f731296027cceb3efad881ae281213f86f","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/ed4cccef64c1d0d5b91e69f7a8a6697c3a865486","tags":["x_transferred"]},{"url":"https://security.netapp.com/advisory/ntap-20250509-0008/"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-05-09T20:03:34.797Z"}}]}}