🛡️ CVE-2024-39301 — kernel

🟡 CVSS 5.5 — Medium ✅ No Known Exploit NVD
5.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

net/9p: fix uninit-value in p9_client_rpc()

In the Linux kernel, the following vulnerability has been resolved:

net/9p: fix uninit-value in p9_client_rpc()

Syzbot with the help of KMSAN reported the following error:

BUG: KMSAN: uninit-value in trace_9p_client_res include/trace/events/9p.h:146 [inline]

BUG: KMSAN: uninit-value in p9_client_rpc+0x1314/0x1340 net/9p/client.c:754

trace_9p_client_res include/trace/events/9p.h:146 [inline]

p9_client_rpc+0x1314/0x1340 net/9p/client.c:754

p9_client_create+0x1551/0x1ff0 net/9p/client.c:1031

v9fs_session_init+0x1b9/0x28e0 fs/9p/v9fs.c:410

v9fs_mount+0xe2/0x12b0 fs/9p/vfs_super.c:122

legacy_get_tree+0x114/0x290 fs/fs_context.c:662

vfs_get_tree+0xa7/0x570 fs/super.c:1797

do_new_mount+0x71f/0x15e0 fs/namespace.c:3352

path_mount+0x742/0x1f20 fs/namespace.c:3679

do_mount fs/namespace.c:3692 [inline]

__do_sys_mount fs/namespace.c:3898 [inline]

__se_sys_mount+0x725/0x810 fs/namespace.c:3875

__x64_sys_mount+0xe4/0x150 fs/namespace.c:3875

do_syscall_64+0xd5/0x1f0

entry_SYSCALL_64_after_hwframe+0x6d/0x75

Uninit was created at:

__alloc_pages+0x9d6/0xe70 mm/page_alloc.c:4598

__alloc_pages_node include/linux/gfp.h:238 [inline]

alloc_pages_node include/linux/gfp.h:261 [inline]

alloc_slab_page mm/slub.c:2175 [inline]

allocate_slab mm/slub.c:2338 [inline]

new_slab+0x2de/0x1400 mm/slub.c:2391

___slab_alloc+0x1184/0x33d0 mm/slub.c:3525

__slab_alloc mm/slub.c:3610 [inline]

__slab_alloc_node mm/slub.c:3663 [inline]

slab_alloc_node mm/slub.c:3835 [inline]

kmem_cache_alloc+0x6d3/0xbe0 mm/slub.c:3852

p9_tag_alloc net/9p/client.c:278 [inline]

p9_client_prepare_req+0x20a/0x1770 net/9p/client.c:641

p9_client_rpc+0x27e/0x1340 net/9p/client.c:688

p9_client_create+0x1551/0x1ff0 net/9p/client.c:1031

v9fs_session_init+0x1b9/0x28e0 fs/9p/v9fs.c:410

v9fs_mount+0xe2/0x12b0 fs/9p/vfs_super.c:122

legacy_get_tree+0x114/0x290 fs/fs_context.c:662

vfs_get_tree+0xa7/0x570 fs/super.c:1797

do_new_mount+0x71f/0x15e0 fs/namespace.c:3352

path_mount+0x742/0x1f20 fs/namespace.c:3679

do_mount fs/namespace.c:3692 [inline]

__do_sys_mount fs/namespace.c:3898 [inline]

__se_sys_mount+0x725/0x810 fs/namespace.c:3875

__x64_sys_mount+0xe4/0x150 fs/namespace.c:3875

do_syscall_64+0xd5/0x1f0

entry_SYSCALL_64_after_hwframe+0x6d/0x75

If p9_check_errors() fails early in p9_client_rpc(), req->rc.tag

will not be properly initialized. However, trace_9p_client_res()

ends up trying to print it out anyway before p9_client_rpc()

finishes.

Fix this issue by assigning default values to p9_fcall fields

such as 'tag' and (just in case KMSAN unearths something new) 'id'

during the tag allocation stage.

How this vulnerability can be exploited

This issue can be reached with local access to the system, attack complexity is low, an attacker needs low-level privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity none, availability high.

Affected software

CVE-2024-39301 is recorded against 2 packages.

  • kernel (from 6.7.0 up to 6.9.5)
  • linux-kernel

Timeline and source

Published on 25 June 2024 and last revised on 15 July 2026. No public exploit is currently recorded for this entry. A vendor advisory or fix has been published. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2024-39301 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Medium
CVSS Score 5.5
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2024-06-25
Updated 2026-08-12
Modified 2026-07-15

Affected Packages

Software From version Fixed in
kernel 6.7.0 6.9.5
linux-kernel

References

Similar Threats

Vulnerability Monitoring

Track new vulnerabilities in kernel

CVE-2024-39301 is rated CVSS 5.5 Medium. BotEraser monitors your WordPress installation and notifies you when software you use appears in our vulnerability database.

Set Up Free Alerts →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.