cbcvebase.
CVE-2024-49850
published 2024-10-21

CVE-2024-49850: In the Linux kernel, the following vulnerability has been resolved: bpf: correctly handle malformed BPF_CORE_TYPE_ID_LOCAL relos In case of malformed…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.9th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: correctly handle malformed BPF_CORE_TYPE_ID_LOCAL relos In case of malformed relocation record of kind BPF_CORE_TYPE_ID_LOCAL referencing a non-existing BTF type, function bpf_core_calc_relo_insn would cause a null pointer deference. Fix this by adding a proper check upper in call stack, as malformed relocation records could be passed from user space. Simplest reproducer is a program: r0 = 0 exit With a single relocation record: .insn_off = 0, /* patch first instruction */ .type_id = 100500, /* this type id does not exist */ .access_str_off = 6, /* offset of string "0" */ .kind = BPF_CORE_TYPE_ID_LOCAL, See the link for original reproducer or next commit for a test case.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 74753e1462e77349525daf9eb60ea21ed92d3a97 < dc7ce14f00bcd50641f2110b7a32aa6552e0780fdc7ce14f00bcd50641f2110b7a32aa6552e0780f
linuxlinux>= 74753e1462e77349525daf9eb60ea21ed92d3a97 < 2288b54b96dcb55bedebcef3572bb8821fc5e7082288b54b96dcb55bedebcef3572bb8821fc5e708
linuxlinux>= 74753e1462e77349525daf9eb60ea21ed92d3a97 < 584cd3ff792e1edbea20b2a7df55897159b0be3e584cd3ff792e1edbea20b2a7df55897159b0be3e
linuxlinux>= 74753e1462e77349525daf9eb60ea21ed92d3a97 < e7e9c5b2dda29067332df2a85b0141a92b41f218e7e9c5b2dda29067332df2a85b0141a92b41f218
linuxlinux>= 74753e1462e77349525daf9eb60ea21ed92d3a97 < 3d2786d65aaa954ebd3fcc033ada433e10da21c43d2786d65aaa954ebd3fcc033ada433e10da21c4
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.11.2-16.11.2-1
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 5.17 < 6.1.1136.1.113
linuxlinux_kernel>= 6.11 < 6.11.26.11.2
linuxlinux_kernel>= 6.2 < 6.6.546.6.54
linuxlinux_kernel>= 6.7 < 6.10.136.10.13
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazl3_kernel_6.6.56.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.