apparmor: Fix null pointer deref when receiving skb during sock creation
In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix null pointer deref when receiving skb during sock creation The panic below is observed when receiving ICMP packets with secmark set while an ICMP raw socket is being created. SK_CTX(sk)->label is updated in apparmor_socket_post_create(), but the packet is delivered to the socket before that, causing the null pointer dereference. Drop the packet if label context is not set. BUG: kernel NULL pointer dereference, address: 000000000000004c #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 0 PID: 407 Comm: a.out Not tainted 6.4.12-arch1-1 #1 3e6fa2753a2d75925c34ecb78e22e85a65d083df Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 05/28/2020 RIP: 0010:aa_label_next_confined+0xb/0x40 Code: 00 00 48 89 ef e8 d5 25 0c 00 e9 66 ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 89 f0 <8b> 77 4c 39 c6 7e 1f 48 63 d0 48 8d 14 d7 eb 0b 83 c0 01 48 83 c2 RSP: 0018:ffffa92940003b08 EFLAGS: 00010246 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 000000000000000e RDX: ffffa92940003be8 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffff8b57471e7800 R08: ffff8b574c642400 R09: 0000000000000002 R10: ffffffffbd820eeb R11: ffffffffbeb7ff00 R12: ffff8b574c642400 R13: 0000000000000001 R14: 0000000000000001 R15: 0000000000000000 FS: 00007fb092ea7640(0000) GS:ffff8b577bc00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000000000000004c CR3: 00000001020f2005 CR4: 00000000007706f0 PKRU: 55555554 Call Trace: <IRQ> ? __die+0x23/0x70 ? page_fault_oops+0x171/0x4e0 ? exc_page_fault+0x7f/0x180 ? asm_exc_page_fault+0x26/0x30 ? aa_label_next_confined+0xb/0x40 apparmor_secmark_check+0xec/0x330 security_sock_rcv_skb+0x35/0x50 sk_filter_trim_cap+0x47/0x250 sock_queue_rcv_skb_reason+0x20/0x60 raw_rcv+0x13c/0x210 raw_local_deliver+0x1f3/0x250 ip_protocol_deliver_rcu+0x4f/0x2f0 ip_local_deliver_finish+0x76/0xa0 __netif_receive_skb_one_core+0x89/0xa0 netif_receive_skb+0x119/0x170 ? __netdev_alloc_skb+0x3d/0x140 vmxnet3_rq_rx_complete+0xb23/0x1010 [vmxnet3 56a84f9c97178c57a43a24ec073b45a9d6f01f3a] vmxnet3_poll_rx_only+0x36/0xb0 [vmxnet3 56a84f9c97178c57a43a24ec073b45a9d6f01f3a] __napi_poll+0x28/0x1b0 net_rx_action+0x2a4/0x380 __do_softirq+0xd1/0x2c8 __irq_exit_rcu+0xbb/0xf0 common_interrupt+0x86/0xa0 </IRQ> <TASK> asm_common_interrupt+0x26/0x40 RIP: 0010:apparmor_socket_post_create+0xb/0x200 Code: 08 48 85 ff 75 a1 eb b1 0f 1f 80 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 41 54 <55> 48 89 fd 53 45 85 c0 0f 84 b2 00 00 00 48 8b 1d 80 56 3f 02 48 RSP: 0018:ffffa92940ce7e50 EFLAGS: 00000286 RAX: ffffffffbc756440 RBX: 0000000000000000 RCX: 0000000000000001 RDX: 0000000000000003 RSI: 0000000000000002 RDI: ffff8b574eaab740 RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000 R10: ffff8b57444cec70 R11: 0000000000000000 R12: 0000000000000003 R13: 0000000000000002 R14: ffff8b574eaab740 R15: ffffffffbd8e4748 ? __pfx_apparmor_socket_post_create+0x10/0x10 security_socket_post_create+0x4b/0x80 __sock_create+0x176/0x1f0 __sys_socket+0x89/0x100 __x64_sys_socket+0x17/0x20 do_syscall_64+0x5d/0x90 ? do_syscall_64+0x6c/0x90 ? do_syscall_64+0x6c/0x90 ? do_syscall_64+0x6c/0x90 entry_SYSCALL_64_after_hwframe+0x72/0xdc
- Published
- Aug 17, 2024
- Updated
- Jun 17, 2026
- EPSS
- 0.2% · 13th percentile
- CWE
- CWE-476
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
22
Monitor
Low priority for now.
- CVSS
- 22 / 40 · 5.5 / 10
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 0 / 30 · 0.2%
CISA SSVC decision
- Exploitation
- none
- Automatable
- no
- Technical impact
- partial
Vulnrichment: CISA's decision-tree inputs.
Affected systems
| Vendor | Product | CPE |
|---|---|---|
| linux | linux kernel | cpe:2.3:o:linux:linux_kernel |
Affected versions
NVD version ranges (for catalog products). Add the product to your stack with a version and matching uses these.
- linux linux kernel4.20 and later · before 5.4.282
- linux linux kernel5.5 and later · before 5.10.224
- linux linux kernel5.11 and later · before 5.15.165
- linux linux kernel5.16 and later · before 6.1.103
- linux linux kernel6.2 and later · before 6.6.44
- linux linux kernel6.7 and later · before 6.10.3
Versions reported by the vendor
Affected version ranges reported by the assigning authority (Linux). Independent of NVD's CPE analysis and usually ahead of it.
Linux Linux
- 4.20affected
- ab9f2115081ab7ba63b77a759e0f3eb5d6463d7f and later · before 0abe35bc48d4ec80424b1f4b3560c0e082cbd5c1affected · git
- ab9f2115081ab7ba63b77a759e0f3eb5d6463d7f and later · before 347dcb84a4874b5fb375092c08d8cc4069b94f81affected · git
- ab9f2115081ab7ba63b77a759e0f3eb5d6463d7f and later · before 290a6b88e8c19b6636ed1acc733d1458206f7697affected · git
- ab9f2115081ab7ba63b77a759e0f3eb5d6463d7f and later · before ead2ad1d9f045f26fdce3ef1644913b3a6cd38f2affected · git
- ab9f2115081ab7ba63b77a759e0f3eb5d6463d7f and later · before 6c920754f62cefc63fccdc38a062c7c3452e2961affected · git
- ab9f2115081ab7ba63b77a759e0f3eb5d6463d7f and later · before 46c17ead5b7389e22e7dc9903fd0ba865d05bda2affected · git
- ab9f2115081ab7ba63b77a759e0f3eb5d6463d7f and later · before fce09ea314505a52f2436397608fa0a5d0934fb1affected · git
- before 4.20not affected · semver
- 5.4.282 and later · up to and including 5.4.*not affected · semver
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| Debian:11 | linux | before 5.10.226-1 | 5.10.226-1 |
| Debian:11 | linux-6.1 | before 6.1.119-1~deb11u1 | 6.1.119-1~deb11u1 |
| Debian:12 | linux | before 6.1.106-1 | 6.1.106-1 |
| Debian:13 | linux | before 6.10.3-1 | 6.10.3-1 |
| openSUSE:Leap 15.6 | dtb-aarch64 | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| openSUSE:Leap 15.6 | kernel-debug | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| openSUSE:Leap 15.6 | kernel-kvmsmall | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| openSUSE:Leap 15.6 | kernel-obs-qa | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Live Patching 15 SP6 | kernel-livepatch-SLE15-SP6_Update_4 | before 1-150600.13.3.3 | 1-150600.13.3.3 |
| SUSE:Linux Enterprise Live Patching 15 SP6 | kernel-livepatch-SLE15-SP6_Update_4 | before 1-150600.13.3.3 | 1-150600.13.3.3 |
| SUSE:Linux Enterprise Live Patching 15 SP6 | kernel-livepatch-SLE15-SP6-RT_Update_2 | before 1-150600.1.3.2 | 1-150600.1.3.2 |
| SUSE:Linux Enterprise Live Patching 15 SP6 | kernel-livepatch-SLE15-SP6-RT_Update_2 | before 1-150600.1.3.2 | 1-150600.1.3.2 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-64kb | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-64kb | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-default | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-default | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-default-base | before 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-default-base | before 6.4.0-150600.23.22.1.150600.12.8.3 | 6.4.0-150600.23.22.1.150600.12.8.3 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-source | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-source | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-zfcpdump | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP6 | kernel-zfcpdump | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP6 | kernel-docs | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP6 | kernel-docs | before 6.4.0-150600.23.22.1 | 6.4.0-150600.23.22.1 |
+26
Same product
linux: all recordsOther highest-scoring records for the same primary product.
- CVE-2022-0847A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe KEV89Now
- CVE-2021-22555Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACEKEV85Now
- CVE-2016-5195Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect haKEV83Now
- CVE-2019-13272In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to creKEV77This week
- CVE-2013-6282The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addKEV77This week
- CVE-2013-2094The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows loKEV77This week
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| Linux Linux | 0abe35bc48d4ec80424b1f4b3560c0e082cbd5c1 | Vendor (CNA) |
| Linux Linux | 290a6b88e8c19b6636ed1acc733d1458206f7697 | Vendor (CNA) |
| Linux Linux | 347dcb84a4874b5fb375092c08d8cc4069b94f81 | Vendor (CNA) |
| Linux Linux | 46c17ead5b7389e22e7dc9903fd0ba865d05bda2 | Vendor (CNA) |
| Linux Linux | 6c920754f62cefc63fccdc38a062c7c3452e2961 | Vendor (CNA) |
| Linux Linux | ead2ad1d9f045f26fdce3ef1644913b3a6cd38f2 | Vendor (CNA) |
| Linux Linux | fce09ea314505a52f2436397608fa0a5d0934fb1 | Vendor (CNA) |
| debian:linux | 6.1.106-1 · Debian:12 | Package registry (OSV) |
| debian:linux-6.1 | 6.1.119-1~deb11u1 · Debian:11 | Package registry (OSV) |
| opensuse:kernel-azure | 6.4.0-150600.8.11.1 · openSUSE:Leap 15.6 | Package registry (OSV) |
| opensuse:kernel-rt | 6.4.0-150600.10.8.3 · openSUSE:Leap 15.6 | Package registry (OSV) |
| opensuse:kernel-source-azure | 6.4.0-150600.8.11.1 · openSUSE:Leap 15.6 | Package registry (OSV) |
| opensuse:kernel-syms-azure | 6.4.0-150600.8.11.1 · openSUSE:Leap 15.6 | Package registry (OSV) |
| suse:kernel-azure | 6.4.0-150600.8.11.1 · SUSE:Linux Enterprise Module for Public Cloud 15 SP6 | Package registry (OSV) |
| suse:kernel-livepatch-SLE15-SP6-RT_Update_2 | 1-150600.1.3.2 · SUSE:Linux Enterprise Live Patching 15 SP6 | Package registry (OSV) |
| suse:kernel-rt | 6.4.0-150600.10.8.3 · SUSE:Real Time Module 15 SP6 | Package registry (OSV) |
| suse:kernel-rt_debug | 6.4.0-150600.10.8.3 · SUSE:Real Time Module 15 SP6 | Package registry (OSV) |
| suse:kernel-source-azure | 6.4.0-150600.8.11.1 · SUSE:Linux Enterprise Module for Public Cloud 15 SP6 | Package registry (OSV) |
| suse:kernel-source-rt | 6.4.0-150600.10.8.3 · SUSE:Real Time Module 15 SP6 | Package registry (OSV) |
| suse:kernel-syms-azure | 6.4.0-150600.8.11.1 · SUSE:Linux Enterprise Module for Public Cloud 15 SP6 | Package registry (OSV) |
| suse:kernel-syms-rt | 6.4.0-150600.10.8.1 · SUSE:Real Time Module 15 SP6 | Package registry (OSV) |
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
No credits in the CNA record.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
Technical details
Attack conditions
- Someone with local access to the system can trigger it.
- A low-privileged account is enough.
- No user action is required.
- No special conditions are required; it is repeatable.
If successful
- Confidentiality
- none
- Integrity
- none
- Availability
- high · the service can be disrupted
- Attack vector
- Local
- Attack complexity
- Low
- Privileges required
- Low
- User interaction
- None
- Scope
- Unchanged
- Confidentiality impact
- None
- Integrity impact
- None
- Availability impact
- High
Weakness class (CWE)
CWE-476 · NULL Pointer DereferenceCVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd-primary
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
MITRE has no CAPEC/ATT&CK mapping for this CWE.
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for all 385,000+ vulnerabilities; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpChange log
- Fix✗ → ✓
For records you follow, these changes also arrive as notifications. →
References
- git.kernel.org/stable/c/0abe35bc48d4ec80424b1f4b3560c0e082cbd5c1
- git.kernel.org/stable/c/290a6b88e8c19b6636ed1acc733d1458206f7697
- git.kernel.org/stable/c/347dcb84a4874b5fb375092c08d8cc4069b94f81
- git.kernel.org/stable/c/46c17ead5b7389e22e7dc9903fd0ba865d05bda2
- git.kernel.org/stable/c/6c920754f62cefc63fccdc38a062c7c3452e2961
- git.kernel.org/stable/c/ead2ad1d9f045f26fdce3ef1644913b3a6cd38f2
- git.kernel.org/stable/c/fce09ea314505a52f2436397608fa0a5d0934fb1
- lists.debian.org/debian-lts-announce/2024/10/msg00003.html
- lists.debian.org/debian-lts-announce/2025/01/msg00001.html
Vendor advisories and official records. Exploit/PoC links are deliberately left out.