Record summary

CVE-2024-27050 has a selected CVSS score of 7.8 (high).

Description

In the Linux kernel, the following vulnerability has been resolved: libbpf: Use OPTS_SET() macro in bpf_xdp_query() When the feature_flags and xdp_zc_max_segs fields were added to the libbpf bpf_xdp_query_opts, the code writing them did not use the OPTS_SET() macro. This causes libbpf to write to those fields unconditionally, which means that programs compiled against an older version of libbpf (with a smaller size of the bpf_xdp_query_opts struct) will have its stack corrupted by libbpf writing out of bounds. The patch adding the feature_flags field has an early bail out if the feature_flags field is not part of the opts struct (via the OPTS_HAS) macro, but the patch adding xdp_zc_max_segs does not. For consistency, this fix just changes the assignments to both fields to use the OPTS_SET() macro.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2024 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unaffected, affected

CVE List13ce2daa259a3bfbc9a5aeeee8b9a87058703731 to < fa5bef5e80c6a3321b2b1a7070436f3bc5daf07caffected
13ce2daa259a3bfbc9a5aeeee8b9a87058703731 to < 682ddd62abd4bdcee7584246903e7a2df005fe0daffected
13ce2daa259a3bfbc9a5aeeee8b9a87058703731 to < cd3be9843247edb8fc6fcd8d8237cbce2bc19f5eaffected
13ce2daa259a3bfbc9a5aeeee8b9a87058703731 to < 92a871ab9fa59a74d013bc04f321026a057618e7affected
6.6affected
Before 6.6unaffected
6.6.23 to ≤ 6.6.*unaffected
6.7.11 to ≤ 6.7.*unaffected
6.8.2 to ≤ 6.8.*unaffected
6.9 to ≤ *unaffected

Default status: unknown

CVE List6.8.2unaffected

Default status: unknown

CVE List6.7.11unaffected
6.6.23unaffected
OSV6.6.0 to < 6.6.23 · Fixed in 6.6.23affected
6.7.0 to < 6.7.11 · Fixed in 6.7.11affected
6.8.0 to < 6.8.2 · Fixed in 6.8.2affected

References

7