cbcvebase.
CVE-2024-26885
published 2024-04-17

CVE-2024-26885: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix DEVMAP_HASH overflow check on 32-bit arches The devmap code allocates a number…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix DEVMAP_HASH overflow check on 32-bit arches The devmap code allocates a number hash buckets equal to the next power of two of the max_entries value provided when creating the map. When rounding up to the next power of two, the 32-bit variable storing the number of buckets can overflow, and the code checks for overflow by checking if the truncated 32-bit value is equal to 0. However, on 32-bit arches the rounding up itself can overflow mid-way through, because it ends up doing a left-shift of 32 bits on an unsigned long value. If the size of an unsigned long is four bytes, this is undefined behaviour, so there is no guarantee that we'll end up with a nice and tidy 0-value at the end. Syzbot managed to turn this into a crash on arm32 by creating a DEVMAP_HASH with max_entries > 0x80000000 and then trying to update it. Fix this by moving the overflow check to before the rounding up operation.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.85-1 (bookworm)linux 6.1.85-1 (bookworm)
linuxlinux
linuxlinux>= 6f9d451ab1a33728adb72d7ff66a7b374d665176 < 1f5e352b9088211fa5eb4e1639cd365f4f7d2f651f5e352b9088211fa5eb4e1639cd365f4f7d2f65
linuxlinux>= 6f9d451ab1a33728adb72d7ff66a7b374d665176 < 4b81a9f92b3676cb74b907a7a209b3d15bd9a7f94b81a9f92b3676cb74b907a7a209b3d15bd9a7f9
linuxlinux>= 6f9d451ab1a33728adb72d7ff66a7b374d665176 < c826502bed93970f2fd488918a7b8d5f1d30e2e3c826502bed93970f2fd488918a7b8d5f1d30e2e3
linuxlinux>= 6f9d451ab1a33728adb72d7ff66a7b374d665176 < edf7990baa48de5097daa9ac02e06cb4c798a737edf7990baa48de5097daa9ac02e06cb4c798a737
linuxlinux>= 6f9d451ab1a33728adb72d7ff66a7b374d665176 < 250051acc21f9d4c5c595e4fcb55986ea08c4691250051acc21f9d4c5c595e4fcb55986ea08c4691
linuxlinux>= 6f9d451ab1a33728adb72d7ff66a7b374d665176 < 22079b3a423382335f47d9ed32114e6c9fe88d7c22079b3a423382335f47d9ed32114e6c9fe88d7c
linuxlinux>= 6f9d451ab1a33728adb72d7ff66a7b374d665176 < e89386f62ce9a9ab9a94835a9890883c23d9d52ce89386f62ce9a9ab9a94835a9890883c23d9d52c
linuxlinux>= 6f9d451ab1a33728adb72d7ff66a7b374d665176 < 281d464a34f540de166cee74b723e97ac2515ec3281d464a34f540de166cee74b723e97ac2515ec3
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.85-16.1.85-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.4.0-200.2205.4.0-200.220
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 0 < 6.8.0-35.356.8.0-35.35
linuxlinux_kernel>= 5.11 < 5.15.1535.15.153
linuxlinux_kernel>= 5.16 < 6.1.836.1.83
linuxlinux_kernel>= 5.4 < 5.10.2145.10.214
linuxlinux_kernel>= 6.2 < 6.6.236.6.23
linuxlinux_kernel>= 6.7 < 6.7.116.7.11
linuxlinux_kernel>= 6.8 < 6.8.26.8.2
msrcazl3_kernel_6.6.22.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.29.1-3_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.