CVE-2024-46695
Last modified
CVE-2024-46695 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on files on an NFS filesystem that is exported with root squashing enabled. The end of the kerneldoc comment for __vfs_setxattr_noperm() states: * This function requires the caller to lock the inode's i_mutex before it * is executed. It also assumes that the caller will make the appropriate * permission checks. nfsd_setattr() does do permissions checking via fh_verify() and nfsd_permission(), but those don't do all the same permissions checks that are done by security_inode_setxattr() and its related LSM hooks do. Since nfsd_setattr() is the only consumer of security_inode_setsecctx(), simplest solution appears to be to replace the call to __vfs_setxattr_noperm() with a call to __vfs_setxattr_locked(). EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on files on an NFS filesystem that is exported with root squashing enabled. The end of the kerneldoc comment for __vfs_setxattr_noperm() states: * This function requires the caller to lock the inode's i_mutex before it * is executed. It also assumes that the caller will make the appropriate * permission checks. nfsd_setattr() does do permissions checking via fh_verify() and nfsd_permission(), but those don't do all the same permissions checks that are done by security_inode_setxattr() and its related LSM hooks do. Since nfsd_setattr() is the only consumer of security_inode_setsecctx(), simplest solution appears to be to replace the call to __vfs_setxattr_noperm() with a call to __vfs_setxattr_locked(). This fixes the above issue and has the added benefit of causing nfsd to recall conflicting delegations on a file when a client tries to change its security label.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | < 6.6.49 | — |
| Linux | Linux Kernel | >= 6.7, < 6.10.8 | — |
| Linux | Linux Kernel | 6.11 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-46695?
How severe is CVE-2024-46695?
How do I fix CVE-2024-46695?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-4669The Events Addon for Elementor plugin for WordPress is vulne…5.4
- CVE-2024-46690In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-46691In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-46692In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-46693In the Linux kernel, the following vulnerability has been re…4.7
- CVE-2024-46694In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-46696In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-46697In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-46698In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2024-46699In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2024-4670The All-in-One Video Gallery plugin for WordPress is vulnera…8.8
- CVE-2024-46700Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2024-46695?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
