cbcvebase.
CVE-2024-50262
published 2024-11-09

CVE-2024-50262: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds write in trie_get_next_key() trie_get_next_key() allocates a node…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.7th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix out-of-bounds write in trie_get_next_key() trie_get_next_key() allocates a node stack with size trie->max_prefixlen, while it writes (trie->max_prefixlen + 1) nodes to the stack when it has full paths from the root to leaves. For example, consider a trie with max_prefixlen is 8, and the nodes with key 0x00/0, 0x00/1, 0x00/2, ... 0x00/8 inserted. Subsequent calls to trie_get_next_key with _key with .prefixlen = 8 make 9 nodes be written on the node stack with size 8.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
debianlinux-6.1< linux 6.1.119-1 (bookworm)linux 6.1.119-1 (bookworm)
linuxlinux
linuxlinux>= b471f2f1de8b816f1e799b80aa92588f3566e4bd < e8494ac079814a53fbc2258d2743e720907488ede8494ac079814a53fbc2258d2743e720907488ed
linuxlinux>= b471f2f1de8b816f1e799b80aa92588f3566e4bd < 91afbc0eb3c90258ae378ae3c6ead3d2371e926d91afbc0eb3c90258ae378ae3c6ead3d2371e926d
linuxlinux>= b471f2f1de8b816f1e799b80aa92588f3566e4bd < 590976f921723d53ac199c01d5b7b73a94875e68590976f921723d53ac199c01d5b7b73a94875e68
linuxlinux>= b471f2f1de8b816f1e799b80aa92588f3566e4bd < 86c8ebe02d8806dd8878d0063e8e185622ab6ea686c8ebe02d8806dd8878d0063e8e185622ab6ea6
linuxlinux>= b471f2f1de8b816f1e799b80aa92588f3566e4bd < a035df0b98df424559fd383e8e1a268f422ea2baa035df0b98df424559fd383e8e1a268f422ea2ba
linuxlinux>= b471f2f1de8b816f1e799b80aa92588f3566e4bd < 90a6e0e1e151ef7a9282e78f54c3091de2dcc99c90a6e0e1e151ef7a9282e78f54c3091de2dcc99c
linuxlinux>= b471f2f1de8b816f1e799b80aa92588f3566e4bd < c4b4f9a9ab82238cb158fa4fe61a8c0ae21a4980c4b4f9a9ab82238cb158fa4fe61a8c0ae21a4980
linuxlinux>= b471f2f1de8b816f1e799b80aa92588f3566e4bd < 13400ac8fb80c57c2bfb12ebd35ee121ce9b4d2113400ac8fb80c57c2bfb12ebd35ee121ce9b4d21
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.119-16.1.119-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 6.11.7-16.11.7-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-133.1445.15.0-133.144
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 4.16 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285
linuxlinux_kernel>= 5.11 < 5.15.1715.15.171
linuxlinux_kernel>= 5.16 < 6.1.1166.1.116
linuxlinux_kernel>= 5.5 < 5.10.2295.10.229

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.