cbcvebase.
CVE-2024-56665
published 2024-12-27

CVE-2024-56665: In the Linux kernel, the following vulnerability has been resolved: bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog Syzbot reported [1]…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.6th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog Syzbot reported [1] crash that happens for following tracing scenario: - create tracepoint perf event with attr.inherit=1, attach it to the process and set bpf program to it - attached process forks -> chid creates inherited event the new child event shares the parent's bpf program and tp_event (hence prog_array) which is global for tracepoint - exit both process and its child -> release both events - first perf_event_detach_bpf_prog call will release tp_event->prog_array and second perf_event_detach_bpf_prog will crash, because tp_event->prog_array is NULL The fix makes sure the perf_event_detach_bpf_prog checks prog_array is valid before it tries to remove the bpf program from it. [1] https://lore.kernel.org/bpf/Z1MR6dCIKajNS6nU@krava/T/#m91dbf0688221ec7a7fc95e896a7ef9ff93b0b8ad

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0ee288e69d033850bc87abe0f9cc3ada24763d7f < dfb15ddf3b65e0df2129f9756d1b4fa78055cdb3dfb15ddf3b65e0df2129f9756d1b4fa78055cdb3
linuxlinux>= 0ee288e69d033850bc87abe0f9cc3ada24763d7f < 978c4486cca5c7b9253d3ab98a88c8e769cb9bbd978c4486cca5c7b9253d3ab98a88c8e769cb9bbd
linuxlinux>= 21db2f35fa97e4a3447f2edeb7b2569a8bfdc83b < c2b6b47662d5f2dfce92e5ffbdcac8229f321d9dc2b6b47662d5f2dfce92e5ffbdcac8229f321d9d
linuxlinux>= 5.15.170 < 5.165.16
linuxlinux>= 6.1.115 < 6.1.1216.1.121
linuxlinux>= 6.11.6 < 6.126.12
linuxlinux>= 6.6.59 < 6.6.676.6.67
linuxlinux>= 7a5c653ede645693422e43cccaa3e8f905d21c74 < 842e5af282453983586e2eae3c8eaf252de5f22f842e5af282453983586e2eae3c8eaf252de5f22f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.15.170 < 5.165.16
linuxlinux_kernel>= 6.1.115 < 6.1.1216.1.121
linuxlinux_kernel>= 6.11.6 < 6.12.66.12.6
linuxlinux_kernel>= 6.6.59 < 6.6.676.6.67
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.