CVE-2024-53119

Description

A flaw was found in the Linux kernel's virtio/vsock subsystem. Due to a race condition during socket destruction, incoming connection requests can be added to the queue after it has already been cleared, leaving unreleased sockets in memory. A local attacker could exploit this timing issue to cause a kernel memory leak, potentially exhausting system resources and leading to a Denial of Service (DoS).

Mitigation

Summary:
Prevent the `vsock` and `vmw_vsock_virtio_transport` kernel modules from loading if virtual socket communication is not required.

Command Instructions:
1. Create a configuration file to prevent loading the modules:

echo "install vsock /bin/true" > /etc/modprobe.d/disable-vsock.conf
echo "install vmw_vsock_virtio_transport /bin/true" >> /etc/modprobe.d/disable-vsock.conf

2. Unload the modules from the running system if currently loaded and not in use:

modprobe -r vmw_vsock_virtio_transport vsock

Caveats:
Disabling these modules halts virtual socket communication (AF_VSOCK) between the host hypervisor and virtual machines. Virtualization features, guest agents, and container utilities that rely on VSOCK will fail to operate.

Warning:
If the modules are in active use and cannot be unloaded dynamically, a system reboot is required for the configuration to take effect.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.15.5N/A
Attack VectorLocalLocalN/A
Attack ComplexityLowLowN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityHighNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactLowHighN/A

Vector

Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart; DoS: Instability; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory)

Most memory leaks result in general product reliability problems, but if an attacker can intentionally trigger a memory leak, the attacker might be able to launch a denial of service attack (by crashing or hanging the program) or take advantage of other unexpected program behavior resulting from a low memory condition.

Other

Technical Impact: Reduce Performance

Frequently Asked Questions

Want to get errata notifications? Sign up here.