cbcvebase.
CVE-2024-38662
published 2024-06-21

CVE-2024-38662: In the Linux kernel, the following vulnerability has been resolved: bpf: Allow delete from sockmap/sockhash only if update is allowed We have seen an influx of…

PriorityP419medium4.7CVSS 3.1
AVLACHPRLUINSUCNIHAN
EPSS
0.22%
12.7th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Allow delete from sockmap/sockhash only if update is allowed We have seen an influx of syzkaller reports where a BPF program attached to a tracepoint triggers a locking rule violation by performing a map_delete on a sockmap/sockhash. We don't intend to support this artificial use scenario. Extend the existing verifier allowed-program-type check for updating sockmap/sockhash to also cover deleting from a map. From now on only BPF programs which were previously allowed to update sockmap/sockhash can delete from these map types.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 5.10.215 < 5.10.2195.10.219
linuxlinux>= 5.15.154 < 5.15.1615.15.161
linuxlinux>= 5.4.274 < 5.55.5
linuxlinux>= 6.1.85 < 6.1.936.1.93
linuxlinux>= 6.6.26 < 6.6.336.6.33
linuxlinux>= 6.8.5 < 6.96.9
linuxlinux>= 668b3074aa14829e2ac2759799537a93b60fef86 < 000a65bf1dc04fb2b65e2abf116f0bc0fc2ee7b1000a65bf1dc04fb2b65e2abf116f0bc0fc2ee7b1
linuxlinux>= a44770fed86515eedb5a7c00b787f847ebb134a5 < 6693b172f008846811f48a099f33effc26068e1e6693b172f008846811f48a099f33effc26068e1e
linuxlinux>= d1e73fb19a4c872d7a399ad3c66e8ca30e0875ec < 11e8ecc5b86037fec43d07b1c162e233e131b1d911e8ecc5b86037fec43d07b1c162e233e131b1d9
linuxlinux>= dd54b48db0c822ae7b520bc80751f0a0a173ef75 < 29467edc23818dc5a33042ffb4920b49b090e63d29467edc23818dc5a33042ffb4920b49b090e63d
linuxlinux>= ff91059932401894e6c86341915615c5eb0eca48 < b81e1c5a3c70398cf76631ede63a03616ed1ba3cb81e1c5a3c70398cf76631ede63a03616ed1ba3c
linuxlinux>= ff91059932401894e6c86341915615c5eb0eca48 < 98e948fb60d41447fd8d2d0c3b8637fc6b6dc26d98e948fb60d41447fd8d2d0c3b8637fc6b6dc26d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.10 < 5.10.2195.10.219
linuxlinux_kernel>= 5.15 < 5.15.1615.15.161

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.