cbcvebase.
CVE-2022-48929
published 2024-08-22

CVE-2022-48929: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix crash due to out of bounds access into reg2btf_ids. When commit e6ac2450d6de…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.3th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix crash due to out of bounds access into reg2btf_ids. When commit e6ac2450d6de ("bpf: Support bpf program calling kernel function") added kfunc support, it defined reg2btf_ids as a cheap way to translate the verifier reg type to the appropriate btf_vmlinux BTF ID, however commit c25b2ae13603 ("bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL") moved the __BPF_REG_TYPE_MAX from the last member of bpf_reg_type enum to after the base register types, and defined other variants using type flag composition. However, now, the direct usage of reg->type to index into reg2btf_ids may no longer fall into __BPF_REG_TYPE_MAX range, and hence lead to out of bounds access and kernel crash on dereference of bad pointer.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.12-1 (bookworm)linux 5.16.12-1 (bookworm)
linuxlinux>= 5.16.11 < 5.16.125.16.12
linuxlinux>= 77459bc4d5e2c6f24db845780b4d9d60cf82d06a < f0ce1bc9e0235dd7412240be493d7ea65ed9eadcf0ce1bc9e0235dd7412240be493d7ea65ed9eadc
linuxlinux>= 8d38cde47a7e17b646401fa92d916503caa5375e < 8c39925e98d498b9531343066ef82ae39e41adae8c39925e98d498b9531343066ef82ae39e41adae
linuxlinux>= c25b2ae136039ffa820c26138ed4a5e5f3ab3841 < 45ce4b4f9009102cd9f581196d480a59208690c145ce4b4f9009102cd9f581196d480a59208690c1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 0 < 5.16.12-15.16.12-1
linuxlinux_kernel>= 5.15.15 < 5.15.375.15.37
linuxlinux_kernel>= 5.16.1 < 5.16.125.16.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.