cbcvebase.
CVE-2024-27431
published 2024-05-17

CVE-2024-27431: In the Linux kernel, the following vulnerability has been resolved: cpumap: Zero-initialise xdp_rxq_info struct before running XDP program When running an XDP…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.1th percentile
In the Linux kernel, the following vulnerability has been resolved: cpumap: Zero-initialise xdp_rxq_info struct before running XDP program When running an XDP program that is attached to a cpumap entry, we don't initialise the xdp_rxq_info data structure being used in the xdp_buff that backs the XDP program invocation. Tobias noticed that this leads to random values being returned as the xdp_md->rx_queue_index value for XDP programs running in a cpumap. This means we're basically returning the contents of the uninitialised memory, which is bad. Fix this by zero-initialising the rxq data structure before running the XDP program.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.82-1 (bookworm)linux 6.1.82-1 (bookworm)
linuxlinux
linuxlinux>= 9216477449f33cdbc9c9a99d49f500b7fbb81702 < 5f4e51abfbe6eb444fa91906a5cd0830442782975f4e51abfbe6eb444fa91906a5cd083044278297
linuxlinux>= 9216477449f33cdbc9c9a99d49f500b7fbb81702 < f0363af9619c77730764f10360e36c6445c12f7bf0363af9619c77730764f10360e36c6445c12f7b
linuxlinux>= 9216477449f33cdbc9c9a99d49f500b7fbb81702 < 3420b3ff1ff489c177ea1cb7bd9fbbc4e9a0be953420b3ff1ff489c177ea1cb7bd9fbbc4e9a0be95
linuxlinux>= 9216477449f33cdbc9c9a99d49f500b7fbb81702 < f562e4c4aab00986dde3093c4be919c3f2b85a4af562e4c4aab00986dde3093c4be919c3f2b85a4a
linuxlinux>= 9216477449f33cdbc9c9a99d49f500b7fbb81702 < eaa7cb836659ced2d9f814ac32aa3ec193803ed6eaa7cb836659ced2d9f814ac32aa3ec193803ed6
linuxlinux>= 9216477449f33cdbc9c9a99d49f500b7fbb81702 < 2487007aa3b9fafbd2cb14068f49791ce1d7ede52487007aa3b9fafbd2cb14068f49791ce1d7ede5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.216-15.10.216-1
linuxlinux_kernel>= 0 < 6.1.82-16.1.82-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 6.7.12-16.7.12-1
linuxlinux_kernel>= 0 < 5.15.0-112.1225.15.0-112.122
linuxlinux_kernel>= 5.11 < 5.15.1525.15.152
linuxlinux_kernel>= 5.16 < 6.1.826.1.82
linuxlinux_kernel>= 5.9 < 5.10.2135.10.213
linuxlinux_kernel>= 6.2 < 6.6.226.6.22

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.