{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-58053","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-03-06T15:52:09.178Z","datePublished":"2025-03-06T15:53:57.558Z","dateUpdated":"2026-08-05T11:47:29.857Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:47:29.857Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix handling of received connection abort\n\nFix the handling of a connection abort that we've received.  Though the\nabort is at the connection level, it needs propagating to the calls on that\nconnection.  Whilst the propagation bit is performed, the calls aren't then\nwoken up to go and process their termination, and as no further input is\nforthcoming, they just hang.\n\nAlso add some tracing for the logging of connection aborts."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The trigger is an unauthenticated rxrpc ABORT packet delivered over UDP to an AF_RXRPC endpoint (kafs binds its callback-manager service to [::]:7001, and client connections accept aborts from the peer), handled entirely in net/rxrpc/io_thread.c → conn_event.c.\nAC:L - The attacker fully controls both steps — send a DATA packet to instantiate a service call on a channel, then send a connection-level ABORT — with no race, no memory-layout dependence, and no reliance on victim state.\nPR:N - The service call is created and attached to conn->channels[] before the rxrpc security challenge/response completes (state SERVICE_UNSECURED/CHALLENGING), and ABORT packets are never authenticated or encrypted, so no credentials of any kind are required.\nUI:N - Exploitation is entirely packet-driven against a listening rxrpc service or an in-flight connection; no action by any local user is needed.\nS:U - The leaked calls, hung RPCs and wedged cleanup path all remain within the kernel's own security authority; no VM, IOMMU or sandbox boundary is crossed.\nC:N - The defect is a missing rxrpc_poke_call() wake-up; no out-of-bounds read, freed-object read, or pointer disclosure occurs.\nI:N - No memory is corrupted and no attacker-controlled data is written anywhere — the only effect is that termination processing never runs.\nA:H - In-flight calls hang indefinitely, each aborted connection permanently leaks up to four rxrpc_call objects (plus conn/peer/local refs and queued skbs) that can be accumulated remotely at packet rate until OOM, and rxrpc_destroy_all_calls()'s wait_var_event() then blocks cleanup_net forever, permanently preventing all network-namespace teardown on the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/trace/events/rxrpc.h","net/rxrpc/conn_event.c"],"versions":[{"version":"248f219cb8bcbfbd7f132752d44afa2df7c241d1","lessThan":"9c6702260557c0183d8417c79a37777a3d3e58e8","status":"affected","versionType":"git"},{"version":"248f219cb8bcbfbd7f132752d44afa2df7c241d1","lessThan":"5842ce7b120c65624052a8da04460d35b26caac0","status":"affected","versionType":"git"},{"version":"248f219cb8bcbfbd7f132752d44afa2df7c241d1","lessThan":"96d1d927c4d03ee9dcee7640bca70b74e63504fc","status":"affected","versionType":"git"},{"version":"248f219cb8bcbfbd7f132752d44afa2df7c241d1","lessThan":"0e56ebde245e4799ce74d38419426f2a80d39950","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/trace/events/rxrpc.h","net/rxrpc/conn_event.c"],"versions":[{"version":"4.9","status":"affected"},{"version":"0","lessThan":"4.9","status":"unaffected","versionType":"semver"},{"version":"6.6.76","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.13","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.13.2","lessThanOrEqual":"6.13.*","status":"unaffected","versionType":"semver"},{"version":"6.14","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.6.76"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.12.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.13.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9","versionEndExcluding":"6.14"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9c6702260557c0183d8417c79a37777a3d3e58e8"},{"url":"https://git.kernel.org/stable/c/5842ce7b120c65624052a8da04460d35b26caac0"},{"url":"https://git.kernel.org/stable/c/96d1d927c4d03ee9dcee7640bca70b74e63504fc"},{"url":"https://git.kernel.org/stable/c/0e56ebde245e4799ce74d38419426f2a80d39950"}],"title":"rxrpc: Fix handling of received connection abort","x_generator":{"engine":"bippy-1.2.0"}}}}