CVE-2024-53099

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
25/11/2024
Last modified:
09/01/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> bpf: Check validity of link-&gt;type in bpf_link_show_fdinfo()<br /> <br /> If a newly-added link type doesn&amp;#39;t invoke BPF_LINK_TYPE(), accessing<br /> bpf_link_type_strs[link-&gt;type] may result in an out-of-bounds access.<br /> <br /> To spot such missed invocations early in the future, checking the<br /> validity of link-&gt;type in bpf_link_show_fdinfo() and emitting a warning<br /> when such invocations are missed.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.62 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.11.9 (excluding)
cpe:2.3:o:linux:linux_kernel:6.12:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.12:rc4:*:*:*:*:*:*