CVE-2024-46831 (GCVE-0-2024-46831)
Vulnerability from cvelistv5
Published
2024-09-27 12:39
Modified
2026-08-05 11:38
Summary
In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: Fix use-after-free error in kunit test This is a clear use-after-free error. We remove it, and rely on checking the return code of vcap_del_rule.
Impacted products
Vendor Product Version
Linux Linux Version: c956b9b318d9036701c471dd458f9ed31defc629
Version: c956b9b318d9036701c471dd458f9ed31defc629
Version: c956b9b318d9036701c471dd458f9ed31defc629
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-46831",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-29T14:03:46.116815Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-29T14:11:44.754Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/microchip/vcap/vcap_api_kunit.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "b0804c286ccfcf5f5c004d5bf8a54c0508b5e86b",
              "status": "affected",
              "version": "c956b9b318d9036701c471dd458f9ed31defc629",
              "versionType": "git"
            },
            {
              "lessThan": "f7fe95f40c85311c98913fe6ae2c56adb7f767a7",
              "status": "affected",
              "version": "c956b9b318d9036701c471dd458f9ed31defc629",
              "versionType": "git"
            },
            {
              "lessThan": "a3c1e45156ad39f225cd7ddae0f81230a3b1e657",
              "status": "affected",
              "version": "c956b9b318d9036701c471dd458f9ed31defc629",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/microchip/vcap/vcap_api_kunit.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.2"
            },
            {
              "lessThan": "6.2",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.51",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.10",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.11",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.51",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.10",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11",
                  "versionStartIncluding": "6.2",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: microchip: vcap: Fix use-after-free error in kunit test\n\nThis is a clear use-after-free error. We remove it, and rely on checking\nthe return code of vcap_del_rule."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is a KUnit test suite executed during kernel initialization on the local system; the only deliberate re-trigger is a write to the local debugfs file /sys/kernel/debug/kunit/VCAP_API_Full_Rule_Testsuite/run. No network, adjacent, or physical path reaches this code \u2014 the test operates entirely on hardcoded local data.\nAC:L - Within an affected build the use-after-free is reached unconditionally and deterministically every boot, requiring no preparation, no race to win, and no memory-layout grooming. Although CONFIG_VCAP_KUNIT_TEST is a non-default developer option, CVSS scores the vulnerable configuration, and within it the trigger is fully reliable.\nPR:N - The kunit suite runs from late_initcall with kunit.enable defaulting to true, so the freed-object accesses execute with no authentication, no capability check, and no privilege gate of any kind on an affected kernel. No credentials are needed for the vulnerable code path to be taken.\nUI:N - The test suite executes automatically during kernel boot without any victim action such as mounting a filesystem, plugging in a device, or opening a file.\nS:U - The corruption is confined to the kernel\u0027s own slab allocator and the VCAP admin rule list within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - This is a use-after-free: freed slab memory is read back as list_head and id fields, and if the slab is reallocated between the kfree() and the reads, those reads pull in whatever data now occupies the chunk. Per kernel scoring guidance a UAF gives attacker influence over freed-object contents and is rated High.\nI:H - Beyond the reported UAF read, the retained dangling node in admin-\u003erules leads vcap_del_rule() to perform list_del() writes into freed memory and a second vcap_free_rule(), producing a double-free plus kfree() of pointers read out of freed memory \u2014 an arbitrary-free/write primitive suitable for heap exploitation.\nA:H - The use-after-free and subsequent double-free corrupt slab metadata and will oops or panic the kernel; on a KUnit-enabled kernel, which commonly runs KASAN, this reliably produces a fatal splat during boot."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:38:53.495Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b0804c286ccfcf5f5c004d5bf8a54c0508b5e86b"
        },
        {
          "url": "https://git.kernel.org/stable/c/f7fe95f40c85311c98913fe6ae2c56adb7f767a7"
        },
        {
          "url": "https://git.kernel.org/stable/c/a3c1e45156ad39f225cd7ddae0f81230a3b1e657"
        }
      ],
      "title": "net: microchip: vcap: Fix use-after-free error in kunit test",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-46831",
    "datePublished": "2024-09-27T12:39:29.078Z",
    "dateReserved": "2024-09-11T15:12:18.286Z",
    "dateUpdated": "2026-08-05T11:38:53.495Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-46831\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-29T14:03:46.116815Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-29T14:03:47.556Z\"}}], \"cna\": {\"title\": \"net: microchip: vcap: Fix use-after-free error in kunit test\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"c956b9b318d9036701c471dd458f9ed31defc629\", \"lessThan\": \"b0804c286ccfcf5f5c004d5bf8a54c0508b5e86b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c956b9b318d9036701c471dd458f9ed31defc629\", \"lessThan\": \"f7fe95f40c85311c98913fe6ae2c56adb7f767a7\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"c956b9b318d9036701c471dd458f9ed31defc629\", \"lessThan\": \"a3c1e45156ad39f225cd7ddae0f81230a3b1e657\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/net/ethernet/microchip/vcap/vcap_api_kunit.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6.2\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"6.2\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.6.51\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.10\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/net/ethernet/microchip/vcap/vcap_api_kunit.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/b0804c286ccfcf5f5c004d5bf8a54c0508b5e86b\"}, {\"url\": \"https://git.kernel.org/stable/c/f7fe95f40c85311c98913fe6ae2c56adb7f767a7\"}, {\"url\": \"https://git.kernel.org/stable/c/a3c1e45156ad39f225cd7ddae0f81230a3b1e657\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnet: microchip: vcap: Fix use-after-free error in kunit test\\n\\nThis is a clear use-after-free error. We remove it, and rely on checking\\nthe return code of vcap_del_rule.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.51\", \"versionStartIncluding\": \"6.2\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.10\", \"versionStartIncluding\": \"6.2\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11\", \"versionStartIncluding\": \"6.2\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-04T09:35:28.677Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-46831\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-05-04T09:35:28.677Z\", \"dateReserved\": \"2024-09-11T15:12:18.286Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-09-27T12:39:29.078Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…