Junglewise Threat Intelligence

CVE-2024-50262: Linux Kernel out-of-bounds write in BPF trie_get_next_key

CVE-2024-50262 · Severity: high · CVSS 7.8 · Published 2024-11-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's BPF subsystem, which is used for high-performance networking and system monitoring. A local attacker could exploit this flaw to cause a system crash or potentially gain unauthorized access to sensitive information by triggering an out-of-bounds memory write. This issue affects various versions of the Linux kernel and could impact the stability and security of servers and workstations.

Technical details

An out-of-bounds write vulnerability exists in the trie_get_next_key() function within kernel/bpf/lpm_trie.c. The function allocates a node stack based on trie->max_prefixlen but fails to account for the additional node required when a full path from root to leaf is traversed, resulting in a write of (max_prefixlen + 1) nodes into a stack of size max_prefixlen. This is a classic off-by-one error in memory allocation. A local attacker with permissions to interact with BPF maps can exploit this to corrupt kernel memory. Patches have been released across multiple stable kernel branches to increase the allocation size to trie->max_prefixlen + 1.

Affected products

  • Linux Linux Kernel 4.16 to 4.19.323, 4.20 to 5.4.285, 5.5 to 5.10.229, 5.11 to 5.15.171, 5.16 to 6.1.116, 6.2 to 6.6.60, 6.7 to 6.11.7, 6.12-rc1 to 6.12-rc5

Timeline

  • 2024-10-26: other: Vulnerability fix authored
  • 2024-11-08: patched: Patches committed to stable trees
  • 2024-11-09: disclosed: Initial disclosure date

References

Related threats