CVE-2024-47678 (GCVE-0-2024-47678)
Vulnerability from cvelistv5
Published
2024-10-21 11:53
Modified
2026-08-05 11:39
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: icmp: change the order of rate limits ICMP messages are ratelimited : After the blamed commits, the two rate limiters are applied in this order: 1) host wide ratelimit (icmp_global_allow()) 2) Per destination ratelimit (inetpeer based) In order to avoid side-channels attacks, we need to apply the per destination check first. This patch makes the following change : 1) icmp_global_allow() checks if the host wide limit is reached. But credits are not yet consumed. This is deferred to 3) 2) The per destination limit is checked/updated. This might add a new node in inetpeer tree. 3) icmp_global_consume() consumes tokens if prior operations succeeded. This means that host wide ratelimit is still effective in keeping inetpeer tree small even under DDOS. As a bonus, I removed icmp_global.lock as the fast path can use a lock-free operation.
Impacted products
Vendor Product Version
Linux Linux Version: 4cdf507d54525842dfd9f6313fdafba039084046
Version: 4cdf507d54525842dfd9f6313fdafba039084046
Version: 4cdf507d54525842dfd9f6313fdafba039084046
Version: 4cdf507d54525842dfd9f6313fdafba039084046
Version: 4cdf507d54525842dfd9f6313fdafba039084046
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-47678",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-21T13:07:41.965400Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-21T13:14:17.106Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:20:43.545Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "include/net/ip.h",
            "net/ipv4/icmp.c",
            "net/ipv6/icmp.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "997ba8889611891f91e8ad83583466aeab6239a3",
              "status": "affected",
              "version": "4cdf507d54525842dfd9f6313fdafba039084046",
              "versionType": "git"
            },
            {
              "lessThan": "662ec52260cc07b9ae53ecd3925183c29d34288b",
              "status": "affected",
              "version": "4cdf507d54525842dfd9f6313fdafba039084046",
              "versionType": "git"
            },
            {
              "lessThan": "a7722921adb046e3836eb84372241f32584bdb07",
              "status": "affected",
              "version": "4cdf507d54525842dfd9f6313fdafba039084046",
              "versionType": "git"
            },
            {
              "lessThan": "483397b4ba280813e4a9c161a0a85172ddb43d19",
              "status": "affected",
              "version": "4cdf507d54525842dfd9f6313fdafba039084046",
              "versionType": "git"
            },
            {
              "lessThan": "8c2bd38b95f75f3d2a08c93e35303e26d480d24e",
              "status": "affected",
              "version": "4cdf507d54525842dfd9f6313fdafba039084046",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "include/net/ip.h",
            "net/ipv4/icmp.c",
            "net/ipv6/icmp.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.18"
            },
            {
              "lessThan": "3.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.113",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.54",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.13",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.2",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "3.18",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nicmp: change the order of rate limits\n\nICMP messages are ratelimited :\n\nAfter the blamed commits, the two rate limiters are applied in this order:\n\n1) host wide ratelimit (icmp_global_allow())\n\n2) Per destination ratelimit (inetpeer based)\n\nIn order to avoid side-channels attacks, we need to apply\nthe per destination check first.\n\nThis patch makes the following change :\n\n1) icmp_global_allow() checks if the host wide limit is reached.\n   But credits are not yet consumed. This is deferred to 3)\n\n2) The per destination limit is checked/updated.\n   This might add a new node in inetpeer tree.\n\n3) icmp_global_consume() consumes tokens if prior operations succeeded.\n\nThis means that host wide ratelimit is still effective\nin keeping inetpeer tree small even under DDOS.\n\nAs a bonus, I removed icmp_global.lock as the fast path\ncan use a lock-free operation."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.4,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable code is the ICMP output rate limiter in the IPv4/IPv6 stack, reached purely by processing received IP packets (e.g. a UDP datagram to a closed port via `__udp4_lib_rcv()` \u2192 `icmp_send()`), and the side channel is measured by an off-path host over the Internet. No local or adjacent access is required.\nAC:L - The attacker fully controls both sides: they generate the packets that drain the global bucket and separately probe its residual state from their own address, repeating at will to average out the `get_random_u32_below(3)` noise, and they can induce the victim resolver\u0027s in-flight query themselves rather than waiting for one. No condition of the target\u0027s memory layout or configuration that the attacker cannot influence is required \u2014 the ordering flaw is deterministic and present in default configurations.\nPR:N - No credentials, sockets, or capabilities are involved anywhere on the path \u2014 ICMP error generation happens for any unsolicited packet before any authentication, from any remote host.\nUI:N - The ICMP replies and the rate-limiter accounting occur entirely in kernel softirq context on packet receipt; no action by any local user or administrator is needed.\nS:U - The leaked state and the resulting impact remain within the security authority of the affected host\u0027s network stack; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The shared global counter leaks whether and how many ICMP-eliciting packets the host processed for arbitrary third-party destinations, which recovers the secret ephemeral UDP source port of in-flight transactions (the SAD DNS primitive); that defeats UDP source-port randomization and exposes the confidentiality of DNS resolution and everything subsequently redirected by it.\nI:H - Recovering the source port lets an off-path attacker forge and win the race against the legitimate response, poisoning the resolver cache and arbitrarily redirecting the victim\u0027s traffic \u2014 full compromise of the integrity of the data the host relies on, consistent with the same attack class scored I:H previously.\nA:L - Because credits are consumed before the per-peer check, a single spoofed source address sending ~50 pps to closed ports exhausts the entire host-wide ICMP budget, suppressing legitimate ICMP error signalling (port unreachable, time exceeded) to every other peer and degrading network diagnostics and fast connection-failure signalling; there is no crash, so the impact is degradation rather than total loss."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:39:24.010Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/997ba8889611891f91e8ad83583466aeab6239a3"
        },
        {
          "url": "https://git.kernel.org/stable/c/662ec52260cc07b9ae53ecd3925183c29d34288b"
        },
        {
          "url": "https://git.kernel.org/stable/c/a7722921adb046e3836eb84372241f32584bdb07"
        },
        {
          "url": "https://git.kernel.org/stable/c/483397b4ba280813e4a9c161a0a85172ddb43d19"
        },
        {
          "url": "https://git.kernel.org/stable/c/8c2bd38b95f75f3d2a08c93e35303e26d480d24e"
        }
      ],
      "title": "icmp: change the order of rate limits",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-47678",
    "datePublished": "2024-10-21T11:53:21.814Z",
    "dateReserved": "2024-09-30T16:00:12.939Z",
    "dateUpdated": "2026-08-05T11:39:24.010Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-47678\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-21T13:07:41.965400Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-10-21T13:07:45.359Z\"}}], \"cna\": {\"title\": \"icmp: change the order of rate limits\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4cdf507d54525842dfd9f6313fdafba039084046\", \"lessThan\": \"997ba8889611891f91e8ad83583466aeab6239a3\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"4cdf507d54525842dfd9f6313fdafba039084046\", \"lessThan\": \"662ec52260cc07b9ae53ecd3925183c29d34288b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"4cdf507d54525842dfd9f6313fdafba039084046\", \"lessThan\": \"a7722921adb046e3836eb84372241f32584bdb07\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"4cdf507d54525842dfd9f6313fdafba039084046\", \"lessThan\": \"483397b4ba280813e4a9c161a0a85172ddb43d19\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"4cdf507d54525842dfd9f6313fdafba039084046\", \"lessThan\": \"8c2bd38b95f75f3d2a08c93e35303e26d480d24e\", \"versionType\": \"git\"}], \"programFiles\": [\"include/net/ip.h\", \"net/ipv4/icmp.c\", \"net/ipv6/icmp.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"3.18\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"3.18\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.1.113\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.54\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.13\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"include/net/ip.h\", \"net/ipv4/icmp.c\", \"net/ipv6/icmp.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/997ba8889611891f91e8ad83583466aeab6239a3\"}, {\"url\": \"https://git.kernel.org/stable/c/662ec52260cc07b9ae53ecd3925183c29d34288b\"}, {\"url\": \"https://git.kernel.org/stable/c/a7722921adb046e3836eb84372241f32584bdb07\"}, {\"url\": \"https://git.kernel.org/stable/c/483397b4ba280813e4a9c161a0a85172ddb43d19\"}, {\"url\": \"https://git.kernel.org/stable/c/8c2bd38b95f75f3d2a08c93e35303e26d480d24e\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nicmp: change the order of rate limits\\n\\nICMP messages are ratelimited :\\n\\nAfter the blamed commits, the two rate limiters are applied in this order:\\n\\n1) host wide ratelimit (icmp_global_allow())\\n\\n2) Per destination ratelimit (inetpeer based)\\n\\nIn order to avoid side-channels attacks, we need to apply\\nthe per destination check first.\\n\\nThis patch makes the following change :\\n\\n1) icmp_global_allow() checks if the host wide limit is reached.\\n   But credits are not yet consumed. This is deferred to 3)\\n\\n2) The per destination limit is checked/updated.\\n   This might add a new node in inetpeer tree.\\n\\n3) icmp_global_consume() consumes tokens if prior operations succeeded.\\n\\nThis means that host wide ratelimit is still effective\\nin keeping inetpeer tree small even under DDOS.\\n\\nAs a bonus, I removed icmp_global.lock as the fast path\\ncan use a lock-free operation.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.113\", \"versionStartIncluding\": \"3.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.54\", \"versionStartIncluding\": \"3.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.13\", \"versionStartIncluding\": \"3.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.2\", \"versionStartIncluding\": \"3.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"3.18\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-04T09:37:04.400Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-47678\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-05-04T09:37:04.400Z\", \"dateReserved\": \"2024-09-30T16:00:12.939Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-10-21T11:53:21.814Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…