🛡️ AZL-53648 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2024-50301 affecting package kernel for versions less than 5.15.173.1-1

In the Linux kernel, the following vulnerability has been resolved:

security/keys: fix slab-out-of-bounds in key_task_permission

KASAN reports an out of bounds read:

BUG: KASAN: slab-out-of-bounds in __kuid_val include/linux/uidgid.h:36

BUG: KASAN: slab-out-of-bounds in uid_eq include/linux/uidgid.h:63 [inline]

BUG: KASAN: slab-out-of-bounds in key_task_permission+0x394/0x410

security/keys/permission.c:54

Read of size 4 at addr ffff88813c3ab618 by task stress-ng/4362

CPU: 2 PID: 4362 Comm: stress-ng Not tainted 5.10.0-14930-gafbffd6c3ede #15

Call Trace:

__dump_stack lib/dump_stack.c:82 [inline]

dump_stack+0x107/0x167 lib/dump_stack.c:123

print_address_description.constprop.0+0x19/0x170 mm/kasan/report.c:400

__kasan_report.cold+0x6c/0x84 mm/kasan/report.c:560

kasan_report+0x3a/0x50 mm/kasan/report.c:585

__kuid_val include/linux/uidgid.h:36 [inline]

uid_eq include/linux/uidgid.h:63 [inline]

key_task_permission+0x394/0x410 security/keys/permission.c:54

search_nested_keyrings+0x90e/0xe90 security/keys/keyring.c:793

This issue was also reported by syzbot.

It can be reproduced by following these steps(more details [1]):

1. Obtain more than 32 inputs that have similar hashes, which ends with the

pattern '0xxxxxxxe6'.

2. Reboot and add the keys obtained in step 1.

The reproducer demonstrates how this issue happened:

1. In the search_nested_keyrings function, when it iterates through the

slots in a node(below tag ascend_to_node), if the slot pointer is meta

and node->back_pointer != NULL(it means a root), it will proceed to

descend_to_node. However, there is an exception. If node is the root,

and one of the slots points to a shortcut, it will be treated as a

keyring.

2. Whether the ptr is keyring decided by keyring_ptr_is_keyring function.

However, KEYRING_PTR_SUBTYPE is 0x2UL, the same as

ASSOC_ARRAY_PTR_SUBTYPE_MASK.

3. When 32 keys with the similar hashes are added to the tree, the ROOT

has keys with hashes that are not similar (e.g. slot 0) and it splits

NODE A without using a shortcut. When NODE A is filled with keys that

all hashes are xxe6, the keys are similar, NODE A will split with a

shortcut. Finally, it forms the tree as shown below, where slot 6 points

to a shortcut.

NODE A

+------>+---+

ROOT | | 0 | xxe6

+---+ | +---+

xxxx | 0 | shortcut : : xxe6

+---+ | +---+

xxe6 : : | | | xxe6

+---+ | +---+

| 6 |---+ : : xxe6

+---+ +---+

xxe6 : : | f | xxe6

+---+ +---+

xxe6 | f |

+---+

4. As mentioned above, If a slot(slot 6) of the root points to a shortcut,

it may be mistakenly transferred to a key*, leading to a read

out-of-bounds read.

To fix this issue, one should jump to descend_to_node if the ptr is a

shortcut, regardless of whether the node is root or not.

[1] https://lore.kernel.org/linux-kernel/[email protected]/

[jarkko: tweaked the commit message a bit to have an appropriate closes

tag.]

Affected software

AZL-53648 is recorded against 1 package.

  • kernel (fixed in 5.15.173.1-1)

Timeline and source

Published on 19 November 2024 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-11-19
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 5.15.173.1-1

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-53648?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-53648 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.