netlink: terminate outstanding dump on socket close

Summary

CVECVE-2024-53140
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2024-12-04 15:15:16 UTC
Updated2026-08-04 11:21:57 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: netlink: terminate outstanding dump on socket close Netlink supports iterative dumping of data. It provides the families the following ops: - start - (optional) kicks off the dumping process - dump - actual dump helper, keeps getting called until it returns 0 - done - (optional) pairs with .start, can be used for cleanup The whole process is asynchronous and the repeated calls to .dump don't actually happen in a tight loop, but rather are triggered in response to recvmsg() on the socket. This gives the user full control over the dump, but also means that the user can close the socket without getting to the end of the dump. To make sure .start is always paired with .done we check if there is an ongoing dump before freeing the socket, and if so call .done. The complication is that sockets can get freed from BH and .done is allowed to sleep. So we use a workqueue to defer the call, when needed. Unfortunately this does not work correctly. What we defer is not the cleanup but rather releasing a reference on the socket. We have no guarantee that we own the last reference, if someone else holds the socket they may release it in BH and we're back to square one. The whole dance, however, appears to be unnecessary. Only the user can interact with dumps, so we can clean up when socket is closed. And close always happens in process context. Some async code may still access the socket after close, queue notification skbs to it etc. but no dumps can start, end or otherwise make progress. Delete the workqueue and flush the dump state directly from the release handler. Note that further cleanup is possible in -next, for instance we now always call .done before releasing the main module reference, so dump doesn't have to take a reference of its own.

Risk And Classification

Primary CVSS: v3.1 5.5 MEDIUM from [email protected]

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem Types: NVD-CWE-noinfo


VersionSourceTypeScoreSeverityVector
3.1[email protected]Primary5.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED7.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Operating System Linux Linux Kernel All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected ed5d7788a934a4b6d6d025e948ed4da496b4f12e 114a61d8d94ae3a43b82446cf737fd757021b834 git Not specified
CNA Linux Linux affected ed5d7788a934a4b6d6d025e948ed4da496b4f12e 598c956b62699c3753929602560d8df322e60559 git Not specified
CNA Linux Linux affected ed5d7788a934a4b6d6d025e948ed4da496b4f12e 6e3f2c512d2b7dbd247485b1dd9e43e4210a18f4 git Not specified
CNA Linux Linux affected ed5d7788a934a4b6d6d025e948ed4da496b4f12e d2fab3d66cc16cfb9e3ea1772abe6b79b71fa603 git Not specified
CNA Linux Linux affected ed5d7788a934a4b6d6d025e948ed4da496b4f12e 4e87a52133284afbd40fb522dbf96e258af52a98 git Not specified
CNA Linux Linux affected ed5d7788a934a4b6d6d025e948ed4da496b4f12e bbc769d2fa1b8b368c5fbe013b5b096afa3c05ca git Not specified
CNA Linux Linux affected ed5d7788a934a4b6d6d025e948ed4da496b4f12e 176c41b3ca9281a9736b67c6121b03dbf0c8c08f git Not specified
CNA Linux Linux affected ed5d7788a934a4b6d6d025e948ed4da496b4f12e 1904fb9ebf911441f90a68e96b22aa73e4410505 git Not specified
CNA Linux Linux affected baaf0c65bc8ea9c7a404b09bc8cc3b8a1e4f18df git Not specified
CNA Linux Linux affected 25d9b4bb64ea964769087fc5ae09aee9c838d759 git Not specified
CNA Linux Linux affected 4.4.38 4.5 semver Not specified
CNA Linux Linux affected 4.8.14 4.9 semver Not specified
CNA Linux Linux affected 4.9 Not specified
CNA Linux Linux unaffected 4.9 semver Not specified
CNA Linux Linux unaffected 4.19.325 4.19.* semver Not specified
CNA Linux Linux unaffected 5.4.287 5.4.* semver Not specified
CNA Linux Linux unaffected 5.10.231 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.174 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.119 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.63 6.6.* semver Not specified
CNA Linux Linux unaffected 6.11.10 6.11.* semver Not specified
CNA Linux Linux unaffected 6.12 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/4e87a52133284afbd40fb522dbf96e258af52a98 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/176c41b3ca9281a9736b67c6121b03dbf0c8c08f 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/6e3f2c512d2b7dbd247485b1dd9e43e4210a18f4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
lists.debian.org/debian-lts-announce/2025/03/msg00002.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org
git.kernel.org/stable/c/1904fb9ebf911441f90a68e96b22aa73e4410505 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/114a61d8d94ae3a43b82446cf737fd757021b834 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
git.kernel.org/stable/c/bbc769d2fa1b8b368c5fbe013b5b096afa3c05ca 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org Patch
lists.debian.org/debian-lts-announce/2025/01/msg00001.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org
git.kernel.org/stable/c/598c956b62699c3753929602560d8df322e60559 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d2fab3d66cc16cfb9e3ea1772abe6b79b71fa603 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report