CVE-2024-47695 (GCVE-0-2024-47695)
Vulnerability from cvelistv5
Published
2024-10-21 11:53
Modified
2026-08-05 11:39
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds In the function init_conns(), after the create_con() and create_cm() for loop if something fails. In the cleanup for loop after the destroy tag, we access out of bound memory because cid is set to clt_path->s.con_num. This commits resets the cid to clt_path->s.con_num - 1, to stay in bounds in the cleanup loop later.
Impacted products
Vendor Product Version
Linux Linux Version: 6a98d71daea186247005099758af549e6afdd244
Version: 6a98d71daea186247005099758af549e6afdd244
Version: 6a98d71daea186247005099758af549e6afdd244
Version: 6a98d71daea186247005099758af549e6afdd244
Version: 6a98d71daea186247005099758af549e6afdd244
Version: 6a98d71daea186247005099758af549e6afdd244
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-47695",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-21T13:05:20.037863Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-21T13:14:14.534Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:20:59.878Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/ulp/rtrs/rtrs-clt.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "0429a4e972082e3a2351da414b1c017daaf8aed2",
              "status": "affected",
              "version": "6a98d71daea186247005099758af549e6afdd244",
              "versionType": "git"
            },
            {
              "lessThan": "5ac73f8191f3de41fef4f934d84d97f3aadb301f",
              "status": "affected",
              "version": "6a98d71daea186247005099758af549e6afdd244",
              "versionType": "git"
            },
            {
              "lessThan": "01b9be936ee8839ab9f83a7e84ee02ac6c8303c4",
              "status": "affected",
              "version": "6a98d71daea186247005099758af549e6afdd244",
              "versionType": "git"
            },
            {
              "lessThan": "1c50e0265fa332c94a4a182e4efa0fc70d8fad94",
              "status": "affected",
              "version": "6a98d71daea186247005099758af549e6afdd244",
              "versionType": "git"
            },
            {
              "lessThan": "c8b7f3d9fada0d4b4b7db86bf7345cd61f1d972e",
              "status": "affected",
              "version": "6a98d71daea186247005099758af549e6afdd244",
              "versionType": "git"
            },
            {
              "lessThan": "3e4289b29e216a55d08a89e126bc0b37cbad9f38",
              "status": "affected",
              "version": "6a98d71daea186247005099758af549e6afdd244",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/ulp/rtrs/rtrs-clt.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "lessThan": "5.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.168",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.10.*",
              "status": "unaffected",
              "version": "6.10.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.168",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.113",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.54",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.10.13",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.2",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds\n\nIn the function init_conns(), after the create_con() and create_cm() for\nloop if something fails. In the cleanup for loop after the destroy tag, we\naccess out of bound memory because cid is set to clt_path-\u003es.con_num.\n\nThis commits resets the cid to clt_path-\u003es.con_num - 1, to stay in bounds\nin the cleanup loop later."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The failure that reaches the out-of-bounds cleanup loop is induced entirely by the remote RTRS server\u0027s `max_hdr_size` field in the RDMA-CM connect-response private data, which flows unvalidated into the `kzalloc()` in `rtrs_iu_alloc()`. RTRS/RNBD runs over RoCEv2 and iWARP, which are IP-routable, so the peer need not be link-local.\nAC:L - The attacker directly controls the exact field (`max_hdr_size`) that makes `alloc_path_reqs()` fail, so the OOB is reached deterministically with no race and no uncontrolled precondition. With `MAX_RECONNECTS = -1` the server can force the reconnect path indefinitely, allowing repeated attempts and heap grooming of the adjacent slab slot.\nPR:N - The rtrs connection handshake performs only a magic/version/errno check and has no authentication whatsoever, so any host able to answer the client\u0027s connect request is implicitly trusted. The attacker holds no credentials or privileges on the victim machine.\nUI:N - Once an rnbd/rtrs session exists as part of normal storage operation, the server simply drops the link and `rtrs_clt_reconnect_work()` re-enters `init_path()` -\u003e `init_conns()` automatically after the reconnect delay. No administrator or user action is required at exploit time.\nS:U - The out-of-bounds read and the subsequent wild-pointer dereferences and free all occur within kernel memory managed by the same security authority. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - `s.con[con_num]` reads uninitialized slab memory past the `kcalloc()`ed array, and that stale value is then dereferenced as a `struct rtrs_clt_con *` through `con-\u003ec.cm_id`, `con-\u003ec.qp`, `con-\u003ec.path`, and `con-\u003ersp_ius`. Combined with the arbitrary-free primitive and the attacker\u0027s ability to groom the neighbouring heap slot across repeated reconnects, this is leverageable into kernel memory disclosure.\nI:H - `destroy_con()` performs `clt_path-\u003es.con[con-\u003ec.cid] = NULL` using a wild base pointer and a wild 32-bit index (a semi-arbitrary NULL write) and then `kfree(con)` on the stale pointer, and `destroy_con_cq_qp()` writes through `con-\u003ec.path` as well. Arbitrary free plus controlled heap corruption is the standard route to control-flow hijack.\nA:H - Even without any grooming, treating stale slab data as a `struct rtrs_clt_con *` and calling `rdma_disconnect()`/`ib_drain_qp()`/`rdma_destroy_id()`/`kfree()` on it reliably oopses or panics the kernel. The remote server can retrigger this on every reconnect cycle indefinitely, taking down the storage client host."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:39:28.289Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/0429a4e972082e3a2351da414b1c017daaf8aed2"
        },
        {
          "url": "https://git.kernel.org/stable/c/5ac73f8191f3de41fef4f934d84d97f3aadb301f"
        },
        {
          "url": "https://git.kernel.org/stable/c/01b9be936ee8839ab9f83a7e84ee02ac6c8303c4"
        },
        {
          "url": "https://git.kernel.org/stable/c/1c50e0265fa332c94a4a182e4efa0fc70d8fad94"
        },
        {
          "url": "https://git.kernel.org/stable/c/c8b7f3d9fada0d4b4b7db86bf7345cd61f1d972e"
        },
        {
          "url": "https://git.kernel.org/stable/c/3e4289b29e216a55d08a89e126bc0b37cbad9f38"
        }
      ],
      "title": "RDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-47695",
    "datePublished": "2024-10-21T11:53:33.266Z",
    "dateReserved": "2024-09-30T16:00:12.942Z",
    "dateUpdated": "2026-08-05T11:39:28.289Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-47695\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-21T13:05:20.037863Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-10-21T13:05:23.222Z\"}}], \"cna\": {\"title\": \"RDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"6a98d71daea186247005099758af549e6afdd244\", \"lessThan\": \"0429a4e972082e3a2351da414b1c017daaf8aed2\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6a98d71daea186247005099758af549e6afdd244\", \"lessThan\": \"5ac73f8191f3de41fef4f934d84d97f3aadb301f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6a98d71daea186247005099758af549e6afdd244\", \"lessThan\": \"01b9be936ee8839ab9f83a7e84ee02ac6c8303c4\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6a98d71daea186247005099758af549e6afdd244\", \"lessThan\": \"1c50e0265fa332c94a4a182e4efa0fc70d8fad94\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6a98d71daea186247005099758af549e6afdd244\", \"lessThan\": \"c8b7f3d9fada0d4b4b7db86bf7345cd61f1d972e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6a98d71daea186247005099758af549e6afdd244\", \"lessThan\": \"3e4289b29e216a55d08a89e126bc0b37cbad9f38\", \"versionType\": \"git\"}], \"programFiles\": [\"drivers/infiniband/ulp/rtrs/rtrs-clt.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.8\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.8\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"5.15.168\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.113\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.54\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.10.13\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.10.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"drivers/infiniband/ulp/rtrs/rtrs-clt.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/0429a4e972082e3a2351da414b1c017daaf8aed2\"}, {\"url\": \"https://git.kernel.org/stable/c/5ac73f8191f3de41fef4f934d84d97f3aadb301f\"}, {\"url\": \"https://git.kernel.org/stable/c/01b9be936ee8839ab9f83a7e84ee02ac6c8303c4\"}, {\"url\": \"https://git.kernel.org/stable/c/1c50e0265fa332c94a4a182e4efa0fc70d8fad94\"}, {\"url\": \"https://git.kernel.org/stable/c/c8b7f3d9fada0d4b4b7db86bf7345cd61f1d972e\"}, {\"url\": \"https://git.kernel.org/stable/c/3e4289b29e216a55d08a89e126bc0b37cbad9f38\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nRDMA/rtrs-clt: Reset cid to con_num - 1 to stay in bounds\\n\\nIn the function init_conns(), after the create_con() and create_cm() for\\nloop if something fails. In the cleanup for loop after the destroy tag, we\\naccess out of bound memory because cid is set to clt_path-\u003es.con_num.\\n\\nThis commits resets the cid to clt_path-\u003es.con_num - 1, to stay in bounds\\nin the cleanup loop later.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.168\", \"versionStartIncluding\": \"5.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.113\", \"versionStartIncluding\": \"5.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.54\", \"versionStartIncluding\": \"5.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.10.13\", \"versionStartIncluding\": \"5.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.2\", \"versionStartIncluding\": \"5.8\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"5.8\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2025-05-04T09:37:34.652Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-47695\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-05-04T09:37:34.652Z\", \"dateReserved\": \"2024-09-30T16:00:12.942Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-10-21T11:53:33.266Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…