{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-40983","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-07-12T12:17:45.604Z","datePublished":"2024-07-12T12:33:57.263Z","dateUpdated":"2026-08-05T11:34:23.838Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:34:23.838Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: force a dst refcount before doing decryption\n\nAs it says in commit 3bc07321ccc2 (\"xfrm: Force a dst refcount before\nentering the xfrm type handlers\"):\n\n\"Crypto requests might return asynchronous. In this case we leave the\n rcu protected region, so force a refcount on the skb's destination\n entry before we enter the xfrm type input/output handlers.\"\n\nOn TIPC decryption path it has the same problem, and skb_dst_force()\nshould be called before doing decryption to avoid a possible crash.\n\nShuang reported this issue when this warning is triggered:\n\n  [] WARNING: include/net/dst.h:337 tipc_sk_rcv+0x1055/0x1ea0 [tipc]\n  [] Kdump: loaded Tainted: G W --------- - - 4.18.0-496.el8.x86_64+debug\n  [] Workqueue: crypto cryptd_queue_worker\n  [] RIP: 0010:tipc_sk_rcv+0x1055/0x1ea0 [tipc]\n  [] Call Trace:\n  [] tipc_sk_mcast_rcv+0x548/0xea0 [tipc]\n  [] tipc_rcv+0xcf5/0x1060 [tipc]\n  [] tipc_aead_decrypt_done+0x215/0x2e0 [tipc]\n  [] cryptd_aead_crypt+0xdb/0x190\n  [] cryptd_queue_worker+0xed/0x190\n  [] process_one_work+0x93d/0x17e0"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug only manifests on the TIPC UDP bearer path (`tipc_udp_recv()` → `tipc_rcv()`, default UDP port 6118), where the skb still carries the noref input-route dst set by `ip_route_input_noref()`; L2 bearers carry no dst at all, so the affected configuration is precisely the routable, remotely reachable one, reachable from any host that can send UDP to the node.\nAC:L - Once TIPC crypto is keyed, every asynchronously completed decryption reaches `__sk_add_backlog()`/`__sock_queue_rcv_skb()` → `skb_dst_force()` from a `cryptd_queue_worker` context outside RCU, tripping `WARN_ON(!rcu_read_lock_held())` deterministically, and the attacker can force the async path at will since `aead_request_set_callback(req, CRYPTO_TFM_REQ_MAY_BACKLOG, ...)` makes a packet flood push requests into the crypto backlog (-EBUSY/-EINPROGRESS), while hardware AEAD offload (QAT/CAAM/CCP) makes it async unconditionally. `CONFIG_TIPC_CRYPTO` is `default y`, so no rare build option is involved, and the attacker can also churn the input-route cache with spoofed sources to widen the window in which the noref dst is actually RCU-freed.\nPR:N - The attacker needs no account, capability, or any privilege on the target host — the path is entered purely by sending TIPC packets to the bearer socket; in TIPC cluster/master-key mode the AEAD key is a single network-wide shared secret held identically by every node, so any peer or compromised cluster member (and an on-path injector replaying an in-flight encrypted frame) reaches the vulnerable code with zero authorization from the vulnerable component.\nUI:N - Delivery of network packets to a configured TIPC bearer is processed entirely by the kernel with no action by any local user or administrator.\nS:U - The stale dst reference, the WARN and any resulting corruption are confined to kernel memory within the same security authority; no VM, IOMMU, container or sandbox boundary is crossed.\nC:H - After the crypto callback leaves the RCU read-side section, `skb_dst_force()` calls `dst_hold_safe()` on a `struct rtable` that may already have been released by `dst_destroy_rcu()`, reading freed slab memory; worse, the skb then loses `SKB_DST_NOREF` and holds what the stack treats as a refcounted pointer into reallocated memory, whose later dereference (`dst->ops`, `dst->dev`) can expose contents of an attacker-groomed object — a use-after-free of this class is treated as High.\nI:H - `dst_hold_safe()` performs a read-modify-write (`rcuref_get`/`atomic_inc_not_zero`) on freed memory, and the subsequent `dst_release()` decrements the same location, giving an attacker who sprays the freed `rtable` slab an increment/decrement primitive plus a premature-free trigger on an unrelated object, including control over the `dst->ops` function-pointer table used on release.\nA:H - The missing refcount reliably trips `WARN_ON(!rcu_read_lock_held())` in `skb_dst_force()` (fatal on the common `panic_on_warn=1` hardened/cloud deployments), and the commit itself states the intent is \"to avoid a possible crash\" — a use-after-free of the dst entry oopses the kernel, and the condition is repeatable on demand by continued packet transmission."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/tipc/node.c"],"versions":[{"version":"fc1b6d6de2208774efd2a20bf0daddb02d18b1e0","lessThan":"3eb1b39627892c4e26cb0162b75725aa5fcc60c8","status":"affected","versionType":"git"},{"version":"fc1b6d6de2208774efd2a20bf0daddb02d18b1e0","lessThan":"692803b39a36e63ac73208e0a3769ae6a2f9bc76","status":"affected","versionType":"git"},{"version":"fc1b6d6de2208774efd2a20bf0daddb02d18b1e0","lessThan":"623c90d86a61e3780f682b32928af469c66ec4c2","status":"affected","versionType":"git"},{"version":"fc1b6d6de2208774efd2a20bf0daddb02d18b1e0","lessThan":"b57a4a2dc8746cea58a922ebe31b6aa629d69d93","status":"affected","versionType":"git"},{"version":"fc1b6d6de2208774efd2a20bf0daddb02d18b1e0","lessThan":"6808b41371670c51feea14f63ade211e78100930","status":"affected","versionType":"git"},{"version":"fc1b6d6de2208774efd2a20bf0daddb02d18b1e0","lessThan":"2ebe8f840c7450ecbfca9d18ac92e9ce9155e269","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/tipc/node.c"],"versions":[{"version":"5.5","status":"affected"},{"version":"0","lessThan":"5.5","status":"unaffected","versionType":"semver"},{"version":"5.10.221","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.162","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.96","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.36","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.9.7","lessThanOrEqual":"6.9.*","status":"unaffected","versionType":"semver"},{"version":"6.10","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.10.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"5.15.162"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.1.96"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.6.36"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.9.7"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.5","versionEndExcluding":"6.10"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3eb1b39627892c4e26cb0162b75725aa5fcc60c8"},{"url":"https://git.kernel.org/stable/c/692803b39a36e63ac73208e0a3769ae6a2f9bc76"},{"url":"https://git.kernel.org/stable/c/623c90d86a61e3780f682b32928af469c66ec4c2"},{"url":"https://git.kernel.org/stable/c/b57a4a2dc8746cea58a922ebe31b6aa629d69d93"},{"url":"https://git.kernel.org/stable/c/6808b41371670c51feea14f63ade211e78100930"},{"url":"https://git.kernel.org/stable/c/2ebe8f840c7450ecbfca9d18ac92e9ce9155e269"}],"title":"tipc: force a dst refcount before doing decryption","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/3eb1b39627892c4e26cb0162b75725aa5fcc60c8","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/692803b39a36e63ac73208e0a3769ae6a2f9bc76","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/623c90d86a61e3780f682b32928af469c66ec4c2","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/b57a4a2dc8746cea58a922ebe31b6aa629d69d93","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/6808b41371670c51feea14f63ade211e78100930","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/2ebe8f840c7450ecbfca9d18ac92e9ce9155e269","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T21:58:47.921Z"}},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-40983","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T17:02:13.493957Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-11T17:34:21.167Z"}}]}}