Remotely exploitable vulnerability in the NVMe-oF/TCP driver within the Linux kernel

A vulnerability (CVE-2023-5178) has been identified in the nvmet-tcp subsystem (NVMe-oF/TCP) of Linux, which allows access to NVMe storage over the network (NVM Express over Fabrics) using the TCP protocol. This vulnerability potentially enables remote code execution at the kernel level or privilege escalation if local access is granted. A patch is currently available for this issue. The problem exists from the very first version of the NVMe-oF/TCP driver (the vulnerability report mentions Linux 5.15, but NVMe-oF/TCP support was added in kernel 5.0). Systems running with proxy server NVMe-oF/TCP (NVME_TARGET_TCP), which by default accepts connections on network port 4420.

The vulnerability is caused by a logical error where the function nvmet_tcp_free_crypto was called twice, freeing certain pointers both times and dereferencing freed addresses. This behavior leads to accessing already freed memory (use-after-free) and double free issues when the NVMe-oF/TCP server processes a specially crafted message from a client that may be located on either the local or the global network.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster