Bug 2219359 (CVE-2023-6176)

Summary: CVE-2023-6176 kernel: local dos vulnerability in scatterwalk_copychunks
Product: [Other] Security Response Reporter: TEJ RATHI <trathi>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: acaringi, allarkin, bhu, chwhite, crwood, dbohanno, ddepaula, debarbos, dfreiber, dvlasenk, ezulian, gnaik, hkrzesin, jarod, jburrell, jdenham, jfaracco, jferlan, jforbes, jlelli, joe.lawrence, jshortt, jstancek, jwyatt, kcarcia, ldoskova, lgoncalv, lleshchi, lzampier, nmurray, ptalbert, qzhao, rogbas, rrobaina, rvrbovsk, rysulliv, scweaver, security-response-team, tglozar, tyberry, vkumar, walters, wcosta, williams, wmealing, ycote, ymankad
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A null pointer dereference flaw was found in the Linux kernel API for the cryptographic algorithm scatterwalk functionality. This issue occurs when a user constructs a malicious packet with specific socket configuration, which could allow a local user to crash the system or escalate their privileges on the system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 2219362, 2219363, 2250069    
Bug Blocks: 2219356    

Description TEJ RATHI 2023-07-03 10:04:40 UTC
When the attacker carefully constructs the network packet to reach the above path, it will execute scatterwalk_copychunks(walk->src.virt.addr, &walk->in, bsize, 0); At this time, the calculated address is 0xdffffc0000000001, which is an invalid kernel address. Accessing this address will panic the kernel, bringing the system crash.

Comment 8 Alex 2023-11-16 13:42:17 UTC
Created kernel tracking bugs for this issue:

Affects: fedora-all [bug 2250069]

Comment 11 Justin M. Forbes 2023-12-19 22:32:22 UTC
This was fixed for Fedora with the 6.5.4 stable kernel updates.