CVE-2024-50301: security/keys: fix slab-out-of-bounds in key_task_permission
In the Linux kernel, the following vulnerability has been resolved:
security/keys: fix slab-out-of-bounds in key_task_permission
KASAN reports an out of bounds read:
BUG: KASAN: slab-out-of-bounds in __kuid_val include/linux/uidgid.h:36
BUG: KASAN: slab-out-of-bounds in uid_eq include/linux/uidgid.h:63 [inline]
BUG: KASAN: slab-out-of-bounds in key_task_permission+0x394/0x410
security/keys/permission.c:54
Read of size 4 at addr ffff88813c3ab618 by task stress-ng/4362
CPU: 2 PID: 4362 Comm: stress-ng Not tainted 5.10.0-14930-gafbffd6c3ede #15
Call Trace:
__dump_stack lib/dump_stack.c:82 [inline]
dump_stack+0x107/0x167 lib/dump_stack.c:123
print_address_description.constprop.0+0x19/0x170 mm/kasan/report.c:400
__kasan_report.cold+0x6c/0x84 mm/kasan/report.c:560
kasan_report+0x3a/0x50 mm/kasan/report.c:585
__kuid_val include/linux/uidgid.h:36 [inline]
uid_eq include/linux/uidgid.h:63 [inline]
key_task_permission+0x394/0x410 security/keys/permission.c:54
search_nested_keyrings+0x90e/0xe90 security/keys/keyring.c:793
This issue was also reported by syzbot.
It can be reproduced by following these steps(more details [1]):
1. Obtain more than 32 inputs that have similar hashes, which ends with the
pattern '0xxxxxxxe6'.
2. Reboot and add the keys obtained in step 1.
The reproducer demonstrates how this issue happened:
1. In the search_nested_keyrings function, when it iterates through the
slots in a node(below tag ascend_to_node), if the slot pointer is meta
and node->back_pointer != NULL(it means a root), it will proceed to
descend_to_node. However, there is an exception. If node is the root,
and one of the slots points to a shortcut, it will be treated as a
keyring.
2. Whether the ptr is keyring decided by keyring_ptr_is_keyring function.
However, KEYRING_PTR_SUBTYPE is 0x2UL, the same as
ASSOC_ARRAY_PTR_SUBTYPE_MASK.
3. When 32 keys with the similar hashes are added to the tree, the ROOT
has keys with hashes that are not similar (e.g. slot 0) and it splits
NODE A without using a shortcut. When NODE A is filled with keys that
all hashes are xxe6, the keys are similar, NODE A will split with a
shortcut. Finally, it forms the tree as shown below, where slot 6 points
to a shortcut.
NODE A
+------>+---+
ROOT | | 0 | xxe6
+---+ | +---+
xxxx | 0 | shortcut : : xxe6
+---+ | +---+
xxe6 : : | | | xxe6
+---+ | +---+
| 6 |---+ : : xxe6
+---+ +---+
xxe6 : : | f | xxe6
+---+ +---+
xxe6 | f |
+---+
4. As mentioned above, If a slot(slot 6) of the root points to a shortcut,
it may be mistakenly transferred to a key*, leading to a read
out-of-bounds read.
To fix this issue, one should jump to descend_to_node if the ptr is a
shortcut, regardless of whether the node is root or not.
[1] https://lore.kernel.org/linux-kernel/1cfa878e-8c7b-4570-8606-21daf5e13ce7@huaweicloud.com/
[jarkko: tweaked the commit message a bit to have an appropriate closes
tag.]
Security readout for executives and security teams
Plain-English summary
CVE-2024-50301 is a Linux kernel bug in the key management subsystem. A local authenticated user could trigger an out-of-bounds read, risking sensitive information exposure or system instability. This is not a remote internet-facing flaw, but it matters on multi-user Linux hosts, shared servers, and systems running untrusted workloads.
Executive priority
Prioritize remediation in the normal high-severity kernel patch cycle, with faster action for shared Linux infrastructure and systems hosting untrusted workloads. The main business risk is local privilege-bound users or workloads causing data exposure or crashes, not unauthenticated remote compromise based on the provided evidence.
Technical view
The flaw is a CWE-125 slab out-of-bounds read in key_task_permission during nested keyring searches. A shortcut pointer in the root node can be misclassified as a keyring pointer, causing invalid memory reads. CVSS 3.1 is 7.1: local attack vector, low complexity, low privileges, no user interaction, high confidentiality and availability impact.
Likely exposure
Exposure is most likely where affected Linux kernels are used and local users, containers, jobs, or services can interact with kernel keyrings. The CVE record lists Linux as affected across multiple stable lines and points to upstream stable fixes. Product-specific exposure depends on distributor and appliance vendor backports.
Exploitation context
The CVE source describes a reproducer and syzbot reporting, but the bundle does not show known active exploitation. KEV is false. Treat this as a locally exploitable kernel memory-safety issue with meaningful risk on shared or workload-dense systems, not as confirmed in-the-wild exploitation.
Researcher notes
Validation should focus on kernel keyring code lineage and whether the stable fix was backported, not only version strings. The source says the fix handles shortcut pointers by descending to the node regardless of root status. No exploit steps should be needed for enterprise validation.
Mitigation direction
Identify Linux kernel versions across servers, appliances, and container hosts.
Apply kernel updates containing the referenced upstream stable fixes.
Use distributor advisories, such as Debian LTS, for packaged kernel remediation.
Check vendor advisories for embedded or industrial products using Linux kernels.
Reduce local untrusted user and workload access until patching completes.
Validation and detection
Confirm running kernel versions against vendor fixed package versions.
Verify the relevant upstream stable commit is present or backported.
Review Debian or product vendor advisories for affected package status.
Prioritize shared hosts, CI runners, container hosts, and appliances first.
Monitor kernel logs for KASAN-like keyring permission crash indicators where available.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-125 · source CWE mapping
Out-of-bounds Read
Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.