cbcvebase.
CVE-2024-53099
published 2024-11-25

CVE-2024-53099: In the Linux kernel, the following vulnerability has been resolved: bpf: Check validity of link->type in bpf_link_show_fdinfo() If a newly-added link type…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.23%
14.2th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Check validity of link->type in bpf_link_show_fdinfo() If a newly-added link type doesn't invoke BPF_LINK_TYPE(), accessing bpf_link_type_strs[link->type] may result in an out-of-bounds access. To spot such missed invocations early in the future, checking the validity of link->type in bpf_link_show_fdinfo() and emitting a warning when such invocations are missed.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 70ed506c3bbcfa846d4636b23051ca79fa4781f7 < 79f87a6ec39fb5968049a6775a528bf58b25c20a79f87a6ec39fb5968049a6775a528bf58b25c20a
linuxlinux>= 70ed506c3bbcfa846d4636b23051ca79fa4781f7 < 24fec234d2ba9ca3c14e545ebe3fd6dcb47f074d24fec234d2ba9ca3c14e545ebe3fd6dcb47f074d
linuxlinux>= 70ed506c3bbcfa846d4636b23051ca79fa4781f7 < 4e8074bb33d18f56af30a0252cb3606d27eb1c134e8074bb33d18f56af30a0252cb3606d27eb1c13
linuxlinux>= 70ed506c3bbcfa846d4636b23051ca79fa4781f7 < d5092b0a1aaf35d77ebd8d33384d7930bec5cb5dd5092b0a1aaf35d77ebd8d33384d7930bec5cb5d
linuxlinux>= 70ed506c3bbcfa846d4636b23051ca79fa4781f7 < b3eb1b6a9f745d6941b345f0fae014dc8bb06d36b3eb1b6a9f745d6941b345f0fae014dc8bb06d36
linuxlinux>= 70ed506c3bbcfa846d4636b23051ca79fa4781f7 < 8421d4c8762bd022cb491f2f0f7019ef51b4f0a78421d4c8762bd022cb491f2f0f7019ef51b4f0a7
linuxlinux_kernel< 6.6.626.6.62
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 6.11.9-16.11.9-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-58.606.8.0-58.60
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 6.7 < 6.11.96.11.9
msrcazl3_kernel_6.6.57.1-7_on_azure_linux_3.0
msrcazl3_kernel_6.6.64.2-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.176.3-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_msrc7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.