cbcvebase.
CVE-2024-40908
published 2024-07-12

CVE-2024-40908: In the Linux kernel, the following vulnerability has been resolved: bpf: Set run context for rawtp test_run callback syzbot reported crash when rawtp program…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
19.9th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Set run context for rawtp test_run callback syzbot reported crash when rawtp program executed through the test_run interface calls bpf_get_attach_cookie helper or any other helper that touches task->bpf_ctx pointer. Setting the run context (task->bpf_ctx pointer) for test_run callback.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
debianlinux-6.1< linux 6.1.99-1 (bookworm)linux 6.1.99-1 (bookworm)
linuxlinux
linuxlinux>= 7adfc6c9b315e174cf8743b21b7b691c8766791b < 789bd77c9342aa6125003871ae5c6034d0f6f9d2789bd77c9342aa6125003871ae5c6034d0f6f9d2
linuxlinux>= 7adfc6c9b315e174cf8743b21b7b691c8766791b < 3708b6c2546c9eb34aead8a34a17e8ae69004e4d3708b6c2546c9eb34aead8a34a17e8ae69004e4d
linuxlinux>= 7adfc6c9b315e174cf8743b21b7b691c8766791b < d387805d4b4a46ee01e3dae133c81b6d80195e5bd387805d4b4a46ee01e3dae133c81b6d80195e5b
linuxlinux>= 7adfc6c9b315e174cf8743b21b7b691c8766791b < ae0ba0ab7475a129ef7d449966edf677367efeb4ae0ba0ab7475a129ef7d449966edf677367efeb4
linuxlinux>= 7adfc6c9b315e174cf8743b21b7b691c8766791b < d0d1df8ba18abc57f28fb3bc053b2bf319367f2cd0d1df8ba18abc57f28fb3bc053b2bf319367f2c
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.99-16.1.99-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 5.15 < 5.15.1625.15.162
linuxlinux_kernel>= 5.16 < 6.1.956.1.95
linuxlinux_kernel>= 6.2 < 6.6.356.6.35
linuxlinux_kernel>= 6.7 < 6.9.66.9.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu6.3MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.