CVE-2024-38566

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/06/2024
Last modified:
17/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf: Fix verifier assumptions about socket-&gt;sk<br /> <br /> The verifier assumes that &amp;#39;sk&amp;#39; field in &amp;#39;struct socket&amp;#39; is valid<br /> and non-NULL when &amp;#39;socket&amp;#39; pointer itself is trusted and non-NULL.<br /> That may not be the case when socket was just created and<br /> passed to LSM socket_accept hook.<br /> Fix this verifier assumption and adjust tests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.4 (including) 6.6.33 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.8.12 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.9 (including) 6.9.3 (excluding)