CVE-2024-35839 (GCVE-0-2024-35839)
Vulnerability from cvelistv5
Published
2024-05-17 14:27
Modified
2026-08-05 11:30
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: replace physindev with physinif in nf_bridge_info An skb can be added to a neigh->arp_queue while waiting for an arp reply. Where original skb's skb->dev can be different to neigh's neigh->dev. For instance in case of bridging dnated skb from one veth to another, the skb would be added to a neigh->arp_queue of the bridge. As skb->dev can be reset back to nf_bridge->physindev and used, and as there is no explicit mechanism that prevents this physindev from been freed under us (for instance neigh_flush_dev doesn't cleanup skbs from different device's neigh queue) we can crash on e.g. this stack: arp_process neigh_update skb = __skb_dequeue(&neigh->arp_queue) neigh_resolve_output(..., skb) ... br_nf_dev_xmit br_nf_pre_routing_finish_bridge_slow skb->dev = nf_bridge->physindev br_handle_frame_finish Let's use plain ifindex instead of net_device link. To peek into the original net_device we will use dev_get_by_index_rcu(). Thus either we get device and are safe to use it or we don't get it and drop skb.
Impacted products
Vendor Product Version
Linux Linux Version: c4e70a87d975d1f561a00abfe2d3cefa2a486c95
Version: c4e70a87d975d1f561a00abfe2d3cefa2a486c95
Version: c4e70a87d975d1f561a00abfe2d3cefa2a486c95
Version: c4e70a87d975d1f561a00abfe2d3cefa2a486c95
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-35839",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-05-23T19:26:55.890240Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-06-04T17:33:44.186Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T03:21:48.411Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/9325e3188a9cf3f69fc6f32af59844bbc5b90547"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/544add1f1cfb78c3dfa3e6edcf4668f6be5e730c"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/9874808878d9eed407e3977fd11fee49de1e1d86"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "include/linux/netfilter_bridge.h",
            "include/linux/skbuff.h",
            "net/bridge/br_netfilter_hooks.c",
            "net/bridge/br_netfilter_ipv6.c",
            "net/ipv4/netfilter/nf_reject_ipv4.c",
            "net/ipv6/netfilter/nf_reject_ipv6.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b",
              "status": "affected",
              "version": "c4e70a87d975d1f561a00abfe2d3cefa2a486c95",
              "versionType": "git"
            },
            {
              "lessThan": "9325e3188a9cf3f69fc6f32af59844bbc5b90547",
              "status": "affected",
              "version": "c4e70a87d975d1f561a00abfe2d3cefa2a486c95",
              "versionType": "git"
            },
            {
              "lessThan": "544add1f1cfb78c3dfa3e6edcf4668f6be5e730c",
              "status": "affected",
              "version": "c4e70a87d975d1f561a00abfe2d3cefa2a486c95",
              "versionType": "git"
            },
            {
              "lessThan": "9874808878d9eed407e3977fd11fee49de1e1d86",
              "status": "affected",
              "version": "c4e70a87d975d1f561a00abfe2d3cefa2a486c95",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "include/linux/netfilter_bridge.h",
            "include/linux/skbuff.h",
            "net/bridge/br_netfilter_hooks.c",
            "net/bridge/br_netfilter_ipv6.c",
            "net/ipv4/netfilter/nf_reject_ipv4.c",
            "net/ipv6/netfilter/nf_reject_ipv6.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.2"
            },
            {
              "lessThan": "4.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.75",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.8",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.75",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.14",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.2",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8",
                  "versionStartIncluding": "4.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: replace physindev with physinif in nf_bridge_info\n\nAn skb can be added to a neigh-\u003earp_queue while waiting for an arp\nreply. Where original skb\u0027s skb-\u003edev can be different to neigh\u0027s\nneigh-\u003edev. For instance in case of bridging dnated skb from one veth to\nanother, the skb would be added to a neigh-\u003earp_queue of the bridge.\n\nAs skb-\u003edev can be reset back to nf_bridge-\u003ephysindev and used, and as\nthere is no explicit mechanism that prevents this physindev from been\nfreed under us (for instance neigh_flush_dev doesn\u0027t cleanup skbs from\ndifferent device\u0027s neigh queue) we can crash on e.g. this stack:\n\narp_process\n  neigh_update\n    skb = __skb_dequeue(\u0026neigh-\u003earp_queue)\n      neigh_resolve_output(..., skb)\n        ...\n          br_nf_dev_xmit\n            br_nf_pre_routing_finish_bridge_slow\n              skb-\u003edev = nf_bridge-\u003ephysindev\n              br_handle_frame_finish\n\nLet\u0027s use plain ifindex instead of net_device link. To peek into the\noriginal net_device we will use dev_get_by_index_rcu(). Thus either we\nget device and are safe to use it or we don\u0027t get it and drop skb."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The full trigger chain requires local control of netdev lifecycle (creating a bridge/veth topology, installing a DNAT rule, and deleting the ingress port) in addition to injecting the packet, all done through netlink/sysctl in the attacker\u0027s own network namespace. Consistent with netfilter/bridge configuration paths being locally reachable.\nAC:L - The attacker deterministically controls every step and their ordering \u2014 DNAT to an address with no neighbour entry, veth deletion, then the ARP reply that dequeues the skb \u2014 and can stretch the arp_queue residency window arbitrarily via the per-netns neigh sysctls (retrans_time_ms/mcast_solicit), giving ample time to reclaim the freed net_device.\nPR:L - An unprivileged user gets CAP_NET_ADMIN in a new netns via `unshare -Urn`, and br_netfilter_sysctl_default() enables bridge-nf-call-iptables/ip6tables by default in every new netns, so no real privilege is needed to arm and reach the path.\nUI:N - The attacker performs the entire sequence \u2014 topology setup, packet injection, device teardown, ARP reply \u2014 with no victim action required.\nS:U - The use-after-free corrupts kernel memory within the same security authority; there is no VM, IOMMU, or hypervisor boundary crossed.\nC:H - Use-after-free on a struct net_device whose fields are re-read after free (dev-\u003end_net, dev-\u003erx_handler_data), giving a reclaim-controlled pointer that is dereferenced \u2014 an arbitrary kernel read primitive once the allocation is sprayed.\nI:H - The freed device\u0027s rx_handler_data is type-confused into a struct net_bridge_port and written through (br_fdb_update), and the attacker-controlled struct net * from dev_net() feeds NF_HOOK\u0027s function-pointer dispatch, enabling arbitrary write and control-flow hijack.\nA:H - Dereferencing the freed net_device reliably oopses/panics the kernel, as observed in the reported production crash stack, and can be triggered repeatedly."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:30:14.444Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b"
        },
        {
          "url": "https://git.kernel.org/stable/c/9325e3188a9cf3f69fc6f32af59844bbc5b90547"
        },
        {
          "url": "https://git.kernel.org/stable/c/544add1f1cfb78c3dfa3e6edcf4668f6be5e730c"
        },
        {
          "url": "https://git.kernel.org/stable/c/9874808878d9eed407e3977fd11fee49de1e1d86"
        }
      ],
      "title": "netfilter: bridge: replace physindev with physinif in nf_bridge_info",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-35839",
    "datePublished": "2024-05-17T14:27:30.524Z",
    "dateReserved": "2024-05-17T13:50:33.104Z",
    "dateUpdated": "2026-08-05T11:30:14.444Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/9325e3188a9cf3f69fc6f32af59844bbc5b90547\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/544add1f1cfb78c3dfa3e6edcf4668f6be5e730c\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/9874808878d9eed407e3977fd11fee49de1e1d86\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T03:21:48.411Z\"}}, {\"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-35839\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-05-23T19:26:55.890240Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-05-23T19:27:01.015Z\"}, \"title\": \"CISA ADP Vulnrichment\"}], \"cna\": {\"title\": \"netfilter: bridge: replace physindev with physinif in nf_bridge_info\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The full trigger chain requires local control of netdev lifecycle (creating a bridge/veth topology, installing a DNAT rule, and deleting the ingress port) in addition to injecting the packet, all done through netlink/sysctl in the attacker\u0027s own network namespace. Consistent with netfilter/bridge configuration paths being locally reachable.\\nAC:L - The attacker deterministically controls every step and their ordering \\u2014 DNAT to an address with no neighbour entry, veth deletion, then the ARP reply that dequeues the skb \\u2014 and can stretch the arp_queue residency window arbitrarily via the per-netns neigh sysctls (retrans_time_ms/mcast_solicit), giving ample time to reclaim the freed net_device.\\nPR:L - An unprivileged user gets CAP_NET_ADMIN in a new netns via `unshare -Urn`, and br_netfilter_sysctl_default() enables bridge-nf-call-iptables/ip6tables by default in every new netns, so no real privilege is needed to arm and reach the path.\\nUI:N - The attacker performs the entire sequence \\u2014 topology setup, packet injection, device teardown, ARP reply \\u2014 with no victim action required.\\nS:U - The use-after-free corrupts kernel memory within the same security authority; there is no VM, IOMMU, or hypervisor boundary crossed.\\nC:H - Use-after-free on a struct net_device whose fields are re-read after free (dev-\u003end_net, dev-\u003erx_handler_data), giving a reclaim-controlled pointer that is dereferenced \\u2014 an arbitrary kernel read primitive once the allocation is sprayed.\\nI:H - The freed device\u0027s rx_handler_data is type-confused into a struct net_bridge_port and written through (br_fdb_update), and the attacker-controlled struct net * from dev_net() feeds NF_HOOK\u0027s function-pointer dispatch, enabling arbitrary write and control-flow hijack.\\nA:H - Dereferencing the freed net_device reliably oopses/panics the kernel, as observed in the reported production crash stack, and can be triggered repeatedly.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"c4e70a87d975d1f561a00abfe2d3cefa2a486c95\", \"lessThan\": \"7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c4e70a87d975d1f561a00abfe2d3cefa2a486c95\", \"lessThan\": \"9325e3188a9cf3f69fc6f32af59844bbc5b90547\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c4e70a87d975d1f561a00abfe2d3cefa2a486c95\", \"lessThan\": \"544add1f1cfb78c3dfa3e6edcf4668f6be5e730c\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c4e70a87d975d1f561a00abfe2d3cefa2a486c95\", \"lessThan\": \"9874808878d9eed407e3977fd11fee49de1e1d86\", \"versionType\": \"git\"}], \"programFiles\": [\"include/linux/netfilter_bridge.h\", \"include/linux/skbuff.h\", \"net/bridge/br_netfilter_hooks.c\", \"net/bridge/br_netfilter_ipv6.c\", \"net/ipv4/netfilter/nf_reject_ipv4.c\", \"net/ipv6/netfilter/nf_reject_ipv6.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.2\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.2\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.75\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.14\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"include/linux/netfilter_bridge.h\", \"include/linux/skbuff.h\", \"net/bridge/br_netfilter_hooks.c\", \"net/bridge/br_netfilter_ipv6.c\", \"net/ipv4/netfilter/nf_reject_ipv4.c\", \"net/ipv6/netfilter/nf_reject_ipv6.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/7ae19ee81ca56b13c50a78de6c47d5b8fdc9d97b\"}, {\"url\": \"https://git.kernel.org/stable/c/9325e3188a9cf3f69fc6f32af59844bbc5b90547\"}, {\"url\": \"https://git.kernel.org/stable/c/544add1f1cfb78c3dfa3e6edcf4668f6be5e730c\"}, {\"url\": \"https://git.kernel.org/stable/c/9874808878d9eed407e3977fd11fee49de1e1d86\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnetfilter: bridge: replace physindev with physinif in nf_bridge_info\\n\\nAn skb can be added to a neigh-\u003earp_queue while waiting for an arp\\nreply. Where original skb\u0027s skb-\u003edev can be different to neigh\u0027s\\nneigh-\u003edev. For instance in case of bridging dnated skb from one veth to\\nanother, the skb would be added to a neigh-\u003earp_queue of the bridge.\\n\\nAs skb-\u003edev can be reset back to nf_bridge-\u003ephysindev and used, and as\\nthere is no explicit mechanism that prevents this physindev from been\\nfreed under us (for instance neigh_flush_dev doesn\u0027t cleanup skbs from\\ndifferent device\u0027s neigh queue) we can crash on e.g. this stack:\\n\\narp_process\\n  neigh_update\\n    skb = __skb_dequeue(\u0026neigh-\u003earp_queue)\\n      neigh_resolve_output(..., skb)\\n        ...\\n          br_nf_dev_xmit\\n            br_nf_pre_routing_finish_bridge_slow\\n              skb-\u003edev = nf_bridge-\u003ephysindev\\n              br_handle_frame_finish\\n\\nLet\u0027s use plain ifindex instead of net_device link. To peek into the\\noriginal net_device we will use dev_get_by_index_rcu(). Thus either we\\nget device and are safe to use it or we don\u0027t get it and drop skb.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.75\", \"versionStartIncluding\": \"4.2\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.14\", \"versionStartIncluding\": \"4.2\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.2\", \"versionStartIncluding\": \"4.2\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8\", \"versionStartIncluding\": \"4.2\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:30:14.444Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-35839\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:30:14.444Z\", \"dateReserved\": \"2024-05-17T13:50:33.104Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-17T14:27:30.524Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…