cbcvebase.
CVE-2024-38566
published 2024-06-19

CVE-2024-38566: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix verifier assumptions about socket->sk The verifier assumes that 'sk' field in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.22%
12.7th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix verifier assumptions about socket->sk The verifier assumes that 'sk' field in 'struct socket' is valid and non-NULL when 'socket' pointer itself is trusted and non-NULL. That may not be the case when socket was just created and passed to LSM socket_accept hook. Fix this verifier assumption and adjust tests.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.8.12-1 (forky)linux 6.8.12-1 (forky)
linuxlinux
linuxlinux>= 6fcd486b3a0a628c41f12b3a7329a18a2c74b351 < 39f8a29330f433000e716eefc4b9abda05b71a8239f8a29330f433000e716eefc4b9abda05b71a82
linuxlinux>= 6fcd486b3a0a628c41f12b3a7329a18a2c74b351 < 6f5ae91172a93abac9720ba94edf3ec8f4d7f24f6f5ae91172a93abac9720ba94edf3ec8f4d7f24f
linuxlinux>= 6fcd486b3a0a628c41f12b3a7329a18a2c74b351 < c58ccdd2483a1d990748cdaf94206b5d5986a001c58ccdd2483a1d990748cdaf94206b5d5986a001
linuxlinux>= 6fcd486b3a0a628c41f12b3a7329a18a2c74b351 < 0db63c0b86e981a1e97d2596d64ceceba1a5470e0db63c0b86e981a1e97d2596d64ceceba1a5470e
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.12-16.8.12-1
linuxlinux_kernel>= 0 < 6.8.0-40.406.8.0-40.40
linuxlinux_kernel>= 6.4 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.8.126.8.12
linuxlinux_kernel>= 6.9 < 6.9.36.9.3

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.