CVE-2024-46763 (GCVE-0-2024-46763)
Vulnerability from cvelistv5
Published
2024-09-18 07:12
Modified
2026-08-05 11:38
Summary
In the Linux kernel, the following vulnerability has been resolved: fou: Fix null-ptr-deref in GRO. We observed a null-ptr-deref in fou_gro_receive() while shutting down a host. [0] The NULL pointer is sk->sk_user_data, and the offset 8 is of protocol in struct fou. When fou_release() is called due to netns dismantle or explicit tunnel teardown, udp_tunnel_sock_release() sets NULL to sk->sk_user_data. Then, the tunnel socket is destroyed after a single RCU grace period. So, in-flight udp4_gro_receive() could find the socket and execute the FOU GRO handler, where sk->sk_user_data could be NULL. Let's use rcu_dereference_sk_user_data() in fou_from_sock() and add NULL checks in FOU GRO handlers. [0]: BUG: kernel NULL pointer dereference, address: 0000000000000008 PF: supervisor read access in kernel mode PF: error_code(0x0000) - not-present page PGD 80000001032f4067 P4D 80000001032f4067 PUD 103240067 PMD 0 SMP PTI CPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.10.216-204.855.amzn2.x86_64 #1 Hardware name: Amazon EC2 c5.large/, BIOS 1.0 10/16/2017 RIP: 0010:fou_gro_receive (net/ipv4/fou.c:233) [fou] Code: 41 5f c3 cc cc cc cc e8 e7 2e 69 f4 0f 1f 80 00 00 00 00 0f 1f 44 00 00 49 89 f8 41 54 48 89 f7 48 89 d6 49 8b 80 88 02 00 00 <0f> b6 48 08 0f b7 42 4a 66 25 fd fd 80 cc 02 66 89 42 4a 0f b6 42 RSP: 0018:ffffa330c0003d08 EFLAGS: 00010297 RAX: 0000000000000000 RBX: ffff93d9e3a6b900 RCX: 0000000000000010 RDX: ffff93d9e3a6b900 RSI: ffff93d9e3a6b900 RDI: ffff93dac2e24d08 RBP: ffff93d9e3a6b900 R08: ffff93dacbce6400 R09: 0000000000000002 R10: 0000000000000000 R11: ffffffffb5f369b0 R12: ffff93dacbce6400 R13: ffff93dac2e24d08 R14: 0000000000000000 R15: ffffffffb4edd1c0 FS: 0000000000000000(0000) GS:ffff93daee800000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000008 CR3: 0000000102140001 CR4: 00000000007706f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: <IRQ> ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259) ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420) ? no_context (arch/x86/mm/fault.c:752) ? exc_page_fault (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 arch/x86/mm/fault.c:1435 arch/x86/mm/fault.c:1483) ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:571) ? fou_gro_receive (net/ipv4/fou.c:233) [fou] udp_gro_receive (include/linux/netdevice.h:2552 net/ipv4/udp_offload.c:559) udp4_gro_receive (net/ipv4/udp_offload.c:604) inet_gro_receive (net/ipv4/af_inet.c:1549 (discriminator 7)) dev_gro_receive (net/core/dev.c:6035 (discriminator 4)) napi_gro_receive (net/core/dev.c:6170) ena_clean_rx_irq (drivers/amazon/net/ena/ena_netdev.c:1558) [ena] ena_io_poll (drivers/amazon/net/ena/ena_netdev.c:1742) [ena] napi_poll (net/core/dev.c:6847) net_rx_action (net/core/dev.c:6917) __do_softirq (arch/x86/include/asm/jump_label.h:25 include/linux/jump_label.h:200 include/trace/events/irq.h:142 kernel/softirq.c:299) asm_call_irq_on_stack (arch/x86/entry/entry_64.S:809) </IRQ> do_softirq_own_stack (arch/x86/include/asm/irq_stack.h:27 arch/x86/include/asm/irq_stack.h:77 arch/x86/kernel/irq_64.c:77) irq_exit_rcu (kernel/softirq.c:393 kernel/softirq.c:423 kernel/softirq.c:435) common_interrupt (arch/x86/kernel/irq.c:239) asm_common_interrupt (arch/x86/include/asm/idtentry.h:626) RIP: 0010:acpi_idle_do_entry (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 drivers/acpi/processor_idle.c:114 drivers/acpi/processor_idle.c:575) Code: 8b 15 d1 3c c4 02 ed c3 cc cc cc cc 65 48 8b 04 25 40 ef 01 00 48 8b 00 a8 08 75 eb 0f 1f 44 00 00 0f 00 2d d5 09 55 00 fb f4 <fa> c3 cc cc cc cc e9 be fc ff ff 66 66 2e 0f 1f 84 00 00 00 00 00 RSP: 0018:ffffffffb5603e58 EFLAGS: 00000246 RAX: 0000000000004000 RBX: ffff93dac0929c00 RCX: ffff93daee833900 RDX: ffff93daee800000 RSI: ffff93d ---truncated---
Impacted products
Vendor Product Version
Linux Linux Version: d92283e338f6d6503b7417536bf3478f466cbc01
Version: d92283e338f6d6503b7417536bf3478f466cbc01
Version: d92283e338f6d6503b7417536bf3478f466cbc01
Version: d92283e338f6d6503b7417536bf3478f466cbc01
Version: d92283e338f6d6503b7417536bf3478f466cbc01
Version: d92283e338f6d6503b7417536bf3478f466cbc01
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-46763",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-29T14:43:18.405859Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-29T14:43:32.083Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:18:09.062Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/ipv4/fou_core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "231c235d2f7a66f018f172e26ffd47c363f244ef",
              "status": "affected",
              "version": "d92283e338f6d6503b7417536bf3478f466cbc01",
              "versionType": "git"
            },
            {
              "lessThan": "4494bccb52ffda22ce5a1163a776d970e6229e08",
              "status": "affected",
              "version": "d92283e338f6d6503b7417536bf3478f466cbc01",
              "versionType": "git"
            },
            {
              "lessThan": "d7567f098f54cb53ee3cee1c82e3d0ed9698b6b3",
              "status": "affected",
              "version": "d92283e338f6d6503b7417536bf3478f466cbc01",
              "versionType": "git"
            },
            {
              "lessThan": "1df42be305fe478ded1ee0c1d775f4ece713483b",
              "status": "affected",
              "version": "d92283e338f6d6503b7417536bf3478f466cbc01",
              "versionType": "git"
            },
            {
              "lessThan": "c46cd6aaca81040deaea3500ba75126963294bd9",
              "status": "affected",
              "version": "d92283e338f6d6503b7417536bf3478f466cbc01",
              "versionType": "git"
            },
            {
              "lessThan": "7e4196935069947d8b70b09c1660b67b067e75cb",
              "status": "affected",
              "version": "d92283e338f6d6503b7417536bf3478f466cbc01",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/ipv4/fou_core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.7"
            },
            {
              "lessThan": "4.7",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.226",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.167",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.110",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.51",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.11",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.226",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.167",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.110",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.51",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.10",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11",
                  "versionStartIncluding": "4.7",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Fix null-ptr-deref in GRO.\n\nWe observed a null-ptr-deref in fou_gro_receive() while shutting down\na host.  [0]\n\nThe NULL pointer is sk-\u003esk_user_data, and the offset 8 is of protocol\nin struct fou.\n\nWhen fou_release() is called due to netns dismantle or explicit tunnel\nteardown, udp_tunnel_sock_release() sets NULL to sk-\u003esk_user_data.\nThen, the tunnel socket is destroyed after a single RCU grace period.\n\nSo, in-flight udp4_gro_receive() could find the socket and execute the\nFOU GRO handler, where sk-\u003esk_user_data could be NULL.\n\nLet\u0027s use rcu_dereference_sk_user_data() in fou_from_sock() and add NULL\nchecks in FOU GRO handlers.\n\n[0]:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\n PF: supervisor read access in kernel mode\n PF: error_code(0x0000) - not-present page\nPGD 80000001032f4067 P4D 80000001032f4067 PUD 103240067 PMD 0\nSMP PTI\nCPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.10.216-204.855.amzn2.x86_64 #1\nHardware name: Amazon EC2 c5.large/, BIOS 1.0 10/16/2017\nRIP: 0010:fou_gro_receive (net/ipv4/fou.c:233) [fou]\nCode: 41 5f c3 cc cc cc cc e8 e7 2e 69 f4 0f 1f 80 00 00 00 00 0f 1f 44 00 00 49 89 f8 41 54 48 89 f7 48 89 d6 49 8b 80 88 02 00 00 \u003c0f\u003e b6 48 08 0f b7 42 4a 66 25 fd fd 80 cc 02 66 89 42 4a 0f b6 42\nRSP: 0018:ffffa330c0003d08 EFLAGS: 00010297\nRAX: 0000000000000000 RBX: ffff93d9e3a6b900 RCX: 0000000000000010\nRDX: ffff93d9e3a6b900 RSI: ffff93d9e3a6b900 RDI: ffff93dac2e24d08\nRBP: ffff93d9e3a6b900 R08: ffff93dacbce6400 R09: 0000000000000002\nR10: 0000000000000000 R11: ffffffffb5f369b0 R12: ffff93dacbce6400\nR13: ffff93dac2e24d08 R14: 0000000000000000 R15: ffffffffb4edd1c0\nFS:  0000000000000000(0000) GS:ffff93daee800000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 0000000102140001 CR4: 00000000007706f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \u003cIRQ\u003e\n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\n ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)\n ? no_context (arch/x86/mm/fault.c:752)\n ? exc_page_fault (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 arch/x86/mm/fault.c:1435 arch/x86/mm/fault.c:1483)\n ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:571)\n ? fou_gro_receive (net/ipv4/fou.c:233) [fou]\n udp_gro_receive (include/linux/netdevice.h:2552 net/ipv4/udp_offload.c:559)\n udp4_gro_receive (net/ipv4/udp_offload.c:604)\n inet_gro_receive (net/ipv4/af_inet.c:1549 (discriminator 7))\n dev_gro_receive (net/core/dev.c:6035 (discriminator 4))\n napi_gro_receive (net/core/dev.c:6170)\n ena_clean_rx_irq (drivers/amazon/net/ena/ena_netdev.c:1558) [ena]\n ena_io_poll (drivers/amazon/net/ena/ena_netdev.c:1742) [ena]\n napi_poll (net/core/dev.c:6847)\n net_rx_action (net/core/dev.c:6917)\n __do_softirq (arch/x86/include/asm/jump_label.h:25 include/linux/jump_label.h:200 include/trace/events/irq.h:142 kernel/softirq.c:299)\n asm_call_irq_on_stack (arch/x86/entry/entry_64.S:809)\n\u003c/IRQ\u003e\n do_softirq_own_stack (arch/x86/include/asm/irq_stack.h:27 arch/x86/include/asm/irq_stack.h:77 arch/x86/kernel/irq_64.c:77)\n irq_exit_rcu (kernel/softirq.c:393 kernel/softirq.c:423 kernel/softirq.c:435)\n common_interrupt (arch/x86/kernel/irq.c:239)\n asm_common_interrupt (arch/x86/include/asm/idtentry.h:626)\nRIP: 0010:acpi_idle_do_entry (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 drivers/acpi/processor_idle.c:114 drivers/acpi/processor_idle.c:575)\nCode: 8b 15 d1 3c c4 02 ed c3 cc cc cc cc 65 48 8b 04 25 40 ef 01 00 48 8b 00 a8 08 75 eb 0f 1f 44 00 00 0f 00 2d d5 09 55 00 fb f4 \u003cfa\u003e c3 cc cc cc cc e9 be fc ff ff 66 66 2e 0f 1f 84 00 00 00 00 00\nRSP: 0018:ffffffffb5603e58 EFLAGS: 00000246\nRAX: 0000000000004000 RBX: ffff93dac0929c00 RCX: ffff93daee833900\nRDX: ffff93daee800000 RSI: ffff93d\n---truncated---"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable code is the UDP GRO receive handler, entered from `udp4_gro_receive()` after a socket-hash lookup on any inbound UDP datagram addressed to the FOU/GUE port. Any remote host that can route a packet to that port reaches `fou_gro_receive()`/`gue_gro_receive()` directly in the NAPI path.\nAC:L - The attacker\u0027s side of the race requires only a sustained stream of ordinary UDP packets, and the NULL window is a full `synchronize_rcu()` grace period (milliseconds), so hitting it is essentially guaranteed rather than a race that must be won. FOU tunnel/netns teardown is a routine recurring event on overlay-network and container hosts, so no special preparation, reconnaissance, or target-specific conditioning is needed.\nPR:N - The GRO handler runs at packet-receive time before any FOU/GUE header validation or tunnel demultiplexing, so no credentials, handshake, or account on the target are involved. The attacker needs no privileges of any kind on the victim system.\nUI:N - No victim is tricked into any action; the crash is delivered purely by inbound packets. The tunnel teardown is an autonomous system/administrative lifecycle event, not user participation in the attack.\nS:U - The NULL dereference and the resulting panic are confined to the kernel of the affected host, with no crossing into another security authority. No hypervisor, IOMMU, or sandbox boundary is bypassed.\nC:N - The fault is a read of NULL+8 that faults immediately; no data is returned to the attacker and no kernel memory contents are disclosed. `mmap_min_addr` and SMAP prevent mapping the zero page to turn this into a controlled read.\nI:N - The bug is a read-only dereference of a NULL pointer with no write to kernel memory and no attacker-controlled value reaching any store. No control-flow hijack or data modification primitive is available.\nA:H - The dereference occurs in softirq/NAPI context, where `oops_end()` unconditionally calls `panic(\"Fatal exception in interrupt\")`, producing a full kernel panic rather than a recoverable oops. This is a complete, unrecoverable denial of service of the entire host."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:38:25.634Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/231c235d2f7a66f018f172e26ffd47c363f244ef"
        },
        {
          "url": "https://git.kernel.org/stable/c/4494bccb52ffda22ce5a1163a776d970e6229e08"
        },
        {
          "url": "https://git.kernel.org/stable/c/d7567f098f54cb53ee3cee1c82e3d0ed9698b6b3"
        },
        {
          "url": "https://git.kernel.org/stable/c/1df42be305fe478ded1ee0c1d775f4ece713483b"
        },
        {
          "url": "https://git.kernel.org/stable/c/c46cd6aaca81040deaea3500ba75126963294bd9"
        },
        {
          "url": "https://git.kernel.org/stable/c/7e4196935069947d8b70b09c1660b67b067e75cb"
        }
      ],
      "title": "fou: Fix null-ptr-deref in GRO.",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-46763",
    "datePublished": "2024-09-18T07:12:22.666Z",
    "dateReserved": "2024-09-11T15:12:18.272Z",
    "dateUpdated": "2026-08-05T11:38:25.634Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/10/msg00003.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:18:09.062Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-46763\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-29T14:43:18.405859Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-29T14:43:22.471Z\"}}], \"cna\": {\"title\": \"fou: Fix null-ptr-deref in GRO.\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.5, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:N - The vulnerable code is the UDP GRO receive handler, entered from `udp4_gro_receive()` after a socket-hash lookup on any inbound UDP datagram addressed to the FOU/GUE port. Any remote host that can route a packet to that port reaches `fou_gro_receive()`/`gue_gro_receive()` directly in the NAPI path.\\nAC:L - The attacker\u0027s side of the race requires only a sustained stream of ordinary UDP packets, and the NULL window is a full `synchronize_rcu()` grace period (milliseconds), so hitting it is essentially guaranteed rather than a race that must be won. FOU tunnel/netns teardown is a routine recurring event on overlay-network and container hosts, so no special preparation, reconnaissance, or target-specific conditioning is needed.\\nPR:N - The GRO handler runs at packet-receive time before any FOU/GUE header validation or tunnel demultiplexing, so no credentials, handshake, or account on the target are involved. The attacker needs no privileges of any kind on the victim system.\\nUI:N - No victim is tricked into any action; the crash is delivered purely by inbound packets. The tunnel teardown is an autonomous system/administrative lifecycle event, not user participation in the attack.\\nS:U - The NULL dereference and the resulting panic are confined to the kernel of the affected host, with no crossing into another security authority. No hypervisor, IOMMU, or sandbox boundary is bypassed.\\nC:N - The fault is a read of NULL+8 that faults immediately; no data is returned to the attacker and no kernel memory contents are disclosed. `mmap_min_addr` and SMAP prevent mapping the zero page to turn this into a controlled read.\\nI:N - The bug is a read-only dereference of a NULL pointer with no write to kernel memory and no attacker-controlled value reaching any store. No control-flow hijack or data modification primitive is available.\\nA:H - The dereference occurs in softirq/NAPI context, where `oops_end()` unconditionally calls `panic(\\\"Fatal exception in interrupt\\\")`, producing a full kernel panic rather than a recoverable oops. This is a complete, unrecoverable denial of service of the entire host.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"d92283e338f6d6503b7417536bf3478f466cbc01\", \"lessThan\": \"231c235d2f7a66f018f172e26ffd47c363f244ef\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d92283e338f6d6503b7417536bf3478f466cbc01\", \"lessThan\": \"4494bccb52ffda22ce5a1163a776d970e6229e08\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d92283e338f6d6503b7417536bf3478f466cbc01\", \"lessThan\": \"d7567f098f54cb53ee3cee1c82e3d0ed9698b6b3\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d92283e338f6d6503b7417536bf3478f466cbc01\", \"lessThan\": \"1df42be305fe478ded1ee0c1d775f4ece713483b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d92283e338f6d6503b7417536bf3478f466cbc01\", \"lessThan\": \"c46cd6aaca81040deaea3500ba75126963294bd9\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"d92283e338f6d6503b7417536bf3478f466cbc01\", \"lessThan\": \"7e4196935069947d8b70b09c1660b67b067e75cb\", \"versionType\": \"git\"}], \"programFiles\": [\"net/ipv4/fou_core.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.7\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.7\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.10.226\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.167\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.110\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.51\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.10\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/ipv4/fou_core.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/231c235d2f7a66f018f172e26ffd47c363f244ef\"}, {\"url\": \"https://git.kernel.org/stable/c/4494bccb52ffda22ce5a1163a776d970e6229e08\"}, {\"url\": \"https://git.kernel.org/stable/c/d7567f098f54cb53ee3cee1c82e3d0ed9698b6b3\"}, {\"url\": \"https://git.kernel.org/stable/c/1df42be305fe478ded1ee0c1d775f4ece713483b\"}, {\"url\": \"https://git.kernel.org/stable/c/c46cd6aaca81040deaea3500ba75126963294bd9\"}, {\"url\": \"https://git.kernel.org/stable/c/7e4196935069947d8b70b09c1660b67b067e75cb\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nfou: Fix null-ptr-deref in GRO.\\n\\nWe observed a null-ptr-deref in fou_gro_receive() while shutting down\\na host.  [0]\\n\\nThe NULL pointer is sk-\u003esk_user_data, and the offset 8 is of protocol\\nin struct fou.\\n\\nWhen fou_release() is called due to netns dismantle or explicit tunnel\\nteardown, udp_tunnel_sock_release() sets NULL to sk-\u003esk_user_data.\\nThen, the tunnel socket is destroyed after a single RCU grace period.\\n\\nSo, in-flight udp4_gro_receive() could find the socket and execute the\\nFOU GRO handler, where sk-\u003esk_user_data could be NULL.\\n\\nLet\u0027s use rcu_dereference_sk_user_data() in fou_from_sock() and add NULL\\nchecks in FOU GRO handlers.\\n\\n[0]:\\nBUG: kernel NULL pointer dereference, address: 0000000000000008\\n PF: supervisor read access in kernel mode\\n PF: error_code(0x0000) - not-present page\\nPGD 80000001032f4067 P4D 80000001032f4067 PUD 103240067 PMD 0\\nSMP PTI\\nCPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.10.216-204.855.amzn2.x86_64 #1\\nHardware name: Amazon EC2 c5.large/, BIOS 1.0 10/16/2017\\nRIP: 0010:fou_gro_receive (net/ipv4/fou.c:233) [fou]\\nCode: 41 5f c3 cc cc cc cc e8 e7 2e 69 f4 0f 1f 80 00 00 00 00 0f 1f 44 00 00 49 89 f8 41 54 48 89 f7 48 89 d6 49 8b 80 88 02 00 00 \u003c0f\u003e b6 48 08 0f b7 42 4a 66 25 fd fd 80 cc 02 66 89 42 4a 0f b6 42\\nRSP: 0018:ffffa330c0003d08 EFLAGS: 00010297\\nRAX: 0000000000000000 RBX: ffff93d9e3a6b900 RCX: 0000000000000010\\nRDX: ffff93d9e3a6b900 RSI: ffff93d9e3a6b900 RDI: ffff93dac2e24d08\\nRBP: ffff93d9e3a6b900 R08: ffff93dacbce6400 R09: 0000000000000002\\nR10: 0000000000000000 R11: ffffffffb5f369b0 R12: ffff93dacbce6400\\nR13: ffff93dac2e24d08 R14: 0000000000000000 R15: ffffffffb4edd1c0\\nFS:  0000000000000000(0000) GS:ffff93daee800000(0000) knlGS:0000000000000000\\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\\nCR2: 0000000000000008 CR3: 0000000102140001 CR4: 00000000007706f0\\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\\nPKRU: 55555554\\nCall Trace:\\n \u003cIRQ\u003e\\n ? show_trace_log_lvl (arch/x86/kernel/dumpstack.c:259)\\n ? __die_body.cold (arch/x86/kernel/dumpstack.c:478 arch/x86/kernel/dumpstack.c:420)\\n ? no_context (arch/x86/mm/fault.c:752)\\n ? exc_page_fault (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 arch/x86/mm/fault.c:1435 arch/x86/mm/fault.c:1483)\\n ? asm_exc_page_fault (arch/x86/include/asm/idtentry.h:571)\\n ? fou_gro_receive (net/ipv4/fou.c:233) [fou]\\n udp_gro_receive (include/linux/netdevice.h:2552 net/ipv4/udp_offload.c:559)\\n udp4_gro_receive (net/ipv4/udp_offload.c:604)\\n inet_gro_receive (net/ipv4/af_inet.c:1549 (discriminator 7))\\n dev_gro_receive (net/core/dev.c:6035 (discriminator 4))\\n napi_gro_receive (net/core/dev.c:6170)\\n ena_clean_rx_irq (drivers/amazon/net/ena/ena_netdev.c:1558) [ena]\\n ena_io_poll (drivers/amazon/net/ena/ena_netdev.c:1742) [ena]\\n napi_poll (net/core/dev.c:6847)\\n net_rx_action (net/core/dev.c:6917)\\n __do_softirq (arch/x86/include/asm/jump_label.h:25 include/linux/jump_label.h:200 include/trace/events/irq.h:142 kernel/softirq.c:299)\\n asm_call_irq_on_stack (arch/x86/entry/entry_64.S:809)\\n\u003c/IRQ\u003e\\n do_softirq_own_stack (arch/x86/include/asm/irq_stack.h:27 arch/x86/include/asm/irq_stack.h:77 arch/x86/kernel/irq_64.c:77)\\n irq_exit_rcu (kernel/softirq.c:393 kernel/softirq.c:423 kernel/softirq.c:435)\\n common_interrupt (arch/x86/kernel/irq.c:239)\\n asm_common_interrupt (arch/x86/include/asm/idtentry.h:626)\\nRIP: 0010:acpi_idle_do_entry (arch/x86/include/asm/irqflags.h:49 arch/x86/include/asm/irqflags.h:89 drivers/acpi/processor_idle.c:114 drivers/acpi/processor_idle.c:575)\\nCode: 8b 15 d1 3c c4 02 ed c3 cc cc cc cc 65 48 8b 04 25 40 ef 01 00 48 8b 00 a8 08 75 eb 0f 1f 44 00 00 0f 00 2d d5 09 55 00 fb f4 \u003cfa\u003e c3 cc cc cc cc e9 be fc ff ff 66 66 2e 0f 1f 84 00 00 00 00 00\\nRSP: 0018:ffffffffb5603e58 EFLAGS: 00000246\\nRAX: 0000000000004000 RBX: ffff93dac0929c00 RCX: ffff93daee833900\\nRDX: ffff93daee800000 RSI: ffff93d\\n---truncated---\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.226\", \"versionStartIncluding\": \"4.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.167\", \"versionStartIncluding\": \"4.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.110\", \"versionStartIncluding\": \"4.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.51\", \"versionStartIncluding\": \"4.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.10\", \"versionStartIncluding\": \"4.7\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11\", \"versionStartIncluding\": \"4.7\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:38:25.634Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-46763\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:38:25.634Z\", \"dateReserved\": \"2024-09-11T15:12:18.272Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-09-18T07:12:22.666Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…