CVE-2024-27061: crypto: sun8i-ce - Fix use after free in unprepare
In the Linux kernel, the following vulnerability has been resolved:
crypto: sun8i-ce - Fix use after free in unprepare
sun8i_ce_cipher_unprepare should be called before
crypto_finalize_skcipher_request, because client callbacks may
immediately free memory, that isn't needed anymore. But it will be
used by unprepare after free. Before removing prepare/unprepare
callbacks it was handled by crypto engine in crypto_finalize_request.
Usually that results in a pointer dereference problem during a in
crypto selftest.
Unable to handle kernel NULL pointer dereference at
virtual address 0000000000000030
Mem abort info:
ESR = 0x0000000096000004
EC = 0x25: DABT (current EL), IL = 32 bits
SET = 0, FnV = 0
EA = 0, S1PTW = 0
FSC = 0x04: level 0 translation fault
Data abort info:
ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000
CM = 0, WnR = 0, TnD = 0, TagAccess = 0
GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0
user pgtable: 4k pages, 48-bit VAs, pgdp=000000004716d000
[0000000000000030] pgd=0000000000000000, p4d=0000000000000000
Internal error: Oops: 0000000096000004 [#1] SMP
This problem is detected by KASAN as well.
==================================================================
BUG: KASAN: slab-use-after-free in sun8i_ce_cipher_do_one+0x6e8/0xf80 [sun8i_ce]
Read of size 8 at addr ffff00000dcdc040 by task 1c15000.crypto-/373
Hardware name: Pine64 PinePhone (1.2) (DT)
Call trace:
dump_backtrace+0x9c/0x128
show_stack+0x20/0x38
dump_stack_lvl+0x48/0x60
print_report+0xf8/0x5d8
kasan_report+0x90/0xd0
__asan_load8+0x9c/0xc0
sun8i_ce_cipher_do_one+0x6e8/0xf80 [sun8i_ce]
crypto_pump_work+0x354/0x620 [crypto_engine]
kthread_worker_fn+0x244/0x498
kthread+0x168/0x178
ret_from_fork+0x10/0x20
Allocated by task 379:
kasan_save_stack+0x3c/0x68
kasan_set_track+0x2c/0x40
kasan_save_alloc_info+0x24/0x38
__kasan_kmalloc+0xd4/0xd8
__kmalloc+0x74/0x1d0
alg_test_skcipher+0x90/0x1f0
alg_test+0x24c/0x830
cryptomgr_test+0x38/0x60
kthread+0x168/0x178
ret_from_fork+0x10/0x20
Freed by task 379:
kasan_save_stack+0x3c/0x68
kasan_set_track+0x2c/0x40
kasan_save_free_info+0x38/0x60
__kasan_slab_free+0x100/0x170
slab_free_freelist_hook+0xd4/0x1e8
__kmem_cache_free+0x15c/0x290
kfree+0x74/0x100
kfree_sensitive+0x80/0xb0
alg_test_skcipher+0x12c/0x1f0
alg_test+0x24c/0x830
cryptomgr_test+0x38/0x60
kthread+0x168/0x178
ret_from_fork+0x10/0x20
The buggy address belongs to the object at ffff00000dcdc000
which belongs to the cache kmalloc-256 of size 256
The buggy address is located 64 bytes inside of
freed 256-byte region [ffff00000dcdc000, ffff00000dcdc100)
Security readout for executives and security teams
Plain-English summary
A Linux kernel crypto-driver ordering flaw can access memory after it has been freed. The supplied evidence shows kernel crashes during crypto self-tests; the CVSS assessment also allows severe confidentiality, integrity, and availability impact. Exposure appears limited to systems using the affected sun8i-ce driver and vulnerable kernel code.
Executive priority
Treat as a high-priority kernel maintenance issue on systems using sun8i-ce, especially those allowing local untrusted users. Expedite inventory and vendor-backed patching, but avoid declaring an emergency fleet-wide compromise: no active exploitation is established, and exposure depends on the affected driver and kernel code.
Technical view
sun8i_ce_cipher_unprepare ran after crypto_finalize_skcipher_request. Because finalization can invoke a client callback that immediately frees request memory, unprepare could subsequently access that freed object. KASAN observed a slab use-after-free in sun8i_ce_cipher_do_one; another trace showed a kernel NULL-pointer dereference. The fix reorders unprepare before finalization.
Likely exposure
Prioritize Linux systems containing and using the sun8i-ce crypto driver. The bundle identifies Linux 6.6, 6.6.24, 6.7.12, and 6.8 as affected, but its version metadata is ambiguous. Confirm exposure using distribution advisories and whether the referenced fix was backported.
Exploitation context
CISA KEV status is false, and the supplied sources do not establish active exploitation. CVSS 3.1 rates it 7.8 with local access and low privileges required. Evidence demonstrates use-after-free and kernel crashes during self-testing, but does not demonstrate practical privilege escalation or code execution.
Researcher notes
The core defect is request-lifecycle ordering across a callback boundary. Finalization may transfer control to code that frees request memory; subsequent unprepare logic then dereferences stale state. The traces substantiate memory-safety failure and denial of service. Broader exploitability is not established by the supplied evidence.
Mitigation direction
Install a vendor-supported kernel containing the applicable referenced stable fix or backport.
Check distribution or device-vendor advisories because the supplied affected-version metadata is ambiguous.
Prioritize shared or user-accessible systems where local low-privilege users increase potential exposure.
Apply vendor-recommended temporary mitigations if an immediate kernel update is unavailable.
Validation and detection
Record the running kernel version and determine whether the sun8i-ce driver is present and used.
Confirm the installed kernel includes the applicable stable commit or a vendor-equivalent backport.
Review kernel logs for sun8i_ce crashes, NULL-pointer dereferences, or KASAN use-after-free reports.
After updating, run vendor-approved crypto and regression tests and monitor kernel logs.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-27061 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.