cbcvebase.
CVE-2024-40909
published 2024-07-12

CVE-2024-40909: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a potential use-after-free in bpf_link_free() After commit 1a80dbcb2dba, bpf_link…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a potential use-after-free in bpf_link_free() After commit 1a80dbcb2dba, bpf_link can be freed by link->ops->dealloc_deferred, but the code still tests and uses link->ops->dealloc afterward, which leads to a use-after-free as reported by syzbot. Actually, one of them should be sufficient, so just call one of them instead of both. Also add a WARN_ON() in case of any problematic implementation.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.9.7-1 (forky)linux 6.9.7-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce < fa97b8fed9896f1e89cb657513e483a152d4c382fa97b8fed9896f1e89cb657513e483a152d4c382
linuxlinux>= 1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce < 2884dc7d08d98a89d8d65121524bb7533183a63a2884dc7d08d98a89d8d65121524bb7533183a63a
linuxlinux>= 6.6.26 < 6.6.356.6.35
linuxlinux>= 6.8.5 < 6.96.9
linuxlinux>= 876941f533e7b47fc69977fc4551c02f2d18af97 < 91cff53136daeff50816b0baeafd38a6976f620991cff53136daeff50816b0baeafd38a6976f6209
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 6.6.26 < 6.6.356.6.35
linuxlinux_kernel>= 6.9 < 6.9.66.9.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.