Junglewise Threat Intelligence

CVE-2024-35905: Linux Kernel integer overflow in BPF verifier stack access

CVE-2024-35905 · Severity: high · CVSS 7.8 · Published 2024-05-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's BPF subsystem could allow a local user to cause a system crash or potentially gain unauthorized access to sensitive data. The issue stems from how the system verifies the size of memory requests, which can be tricked into performing operations outside of intended boundaries. This affects systems running specific versions of the Linux operating system, commonly used in servers and cloud infrastructure.

Technical details

An integer overflow vulnerability exists in the Linux kernel's BPF verifier within the check_stack_range_initialized() function. The root cause is the lack of protection against stack access sizes that appear negative due to signed integer overflow. An attacker with local access can provide a specially crafted BPF program with a non-sensical access size that bypasses verification checks, leading to out-of-bounds array accesses. This could result in local privilege escalation or a denial of service (system crash). The issue was a regression introduced by the removal of indirect checks in a previous commit (a833a17aeac7) and has been patched in multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 5.10.209 to 5.10.215, 5.15.148 to 5.15.154, 6.1.75 to 6.1.85, 6.6.14 to 6.6.26, 6.7.2 to 6.8.5

Timeline

  • 2024-03-26: disclosed: Initial patch authored
  • 2024-04-10: patched: Commits merged into stable branches
  • 2024-05-19: advisory: CVE published by NVD

References