cbcvebase.
CVE-2024-56675
published 2024-12-27

CVE-2024-56675: In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors Uprobes always use…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix UAF via mismatching bpf_prog/attachment RCU flavors Uprobes always use bpf_prog_run_array_uprobe() under tasks-trace-RCU protection. But it is possible to attach a non-sleepable BPF program to a uprobe, and non-sleepable BPF programs are freed via normal RCU (see __bpf_prog_put_noref()). This leads to UAF of the bpf_prog because a normal RCU grace period does not imply a tasks-trace-RCU grace period. Fix it by explicitly waiting for a tasks-trace-RCU grace period after removing the attachment of a bpf_prog to a perf_event.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
debianlinux-6.1< linux 6.1.123-1 (bookworm)linux 6.1.123-1 (bookworm)
linuxlinux
linuxlinux>= 8c7dcb84e3b744b2b70baa7a44a9b1881c33a9c9 < 9245459a992d22fe0e92e988f49db1fec82c184a9245459a992d22fe0e92e988f49db1fec82c184a
linuxlinux>= 8c7dcb84e3b744b2b70baa7a44a9b1881c33a9c9 < f9f85df30118f3f4112761e6682fc60ebcce23e5f9f85df30118f3f4112761e6682fc60ebcce23e5
linuxlinux>= 8c7dcb84e3b744b2b70baa7a44a9b1881c33a9c9 < 9b53d2c2a38a1effc341d99be3f99fa7ef17047d9b53d2c2a38a1effc341d99be3f99fa7ef17047d
linuxlinux>= 8c7dcb84e3b744b2b70baa7a44a9b1881c33a9c9 < ef1b808e3b7c98612feceedf985c2fbbeb28f956ef1b808e3b7c98612feceedf985c2fbbeb28f956
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.123-16.1.123-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.12.6-16.12.6-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 6.0 < 6.1.1216.1.121
linuxlinux_kernel>= 6.2 < 6.6.676.6.67
linuxlinux_kernel>= 6.7 < 6.12.66.12.6
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0
msrcazl3_kernel_6.6.76.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.