CVE-2024-27050
libbpf: Use OPTS_SET() macro in bpf_xdp_query()
Record summary
CVE-2024-27050 has a selected CVSS score of 7.8 (high).
Description
In the Linux kernel, the following vulnerability has been resolved: libbpf: Use OPTS_SET() macro in bpf_xdp_query() When the feature_flags and xdp_zc_max_segs fields were added to the libbpf bpf_xdp_query_opts, the code writing them did not use the OPTS_SET() macro. This causes libbpf to write to those fields unconditionally, which means that programs compiled against an older version of libbpf (with a smaller size of the bpf_xdp_query_opts struct) will have its stack corrupted by libbpf writing out of bounds. The patch adding the feature_flags field has an early bail out if the feature_flags field is not part of the opts struct (via the OPTS_HAS) macro, but the patch adding xdp_zc_max_segs does not. For consistency, this fix just changes the assignments to both fields to use the OPTS_SET() macro.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2024 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
LinuxBrowse Linux / LinuxDefault status: unaffected, affected | CVE List | 13ce2daa259a3bfbc9a5aeeee8b9a87058703731 to < fa5bef5e80c6a3321b2b1a7070436f3bc5daf07c | affected |
| 13ce2daa259a3bfbc9a5aeeee8b9a87058703731 to < 682ddd62abd4bdcee7584246903e7a2df005fe0d | affected | ||
| 13ce2daa259a3bfbc9a5aeeee8b9a87058703731 to < cd3be9843247edb8fc6fcd8d8237cbce2bc19f5e | affected | ||
| 13ce2daa259a3bfbc9a5aeeee8b9a87058703731 to < 92a871ab9fa59a74d013bc04f321026a057618e7 | affected | ||
| 6.6 | affected | ||
| Before 6.6 | unaffected | ||
| 6.6.23 to ≤ 6.6.* | unaffected | ||
| 6.7.11 to ≤ 6.7.* | unaffected | ||
| 6.8.2 to ≤ 6.8.* | unaffected | ||
| 6.9 to ≤ * | unaffected | ||
Default status: unknown | CVE List | 6.8.2 | unaffected |
linux_kernelBrowse linux / linux_kernelDefault status: unknown | CVE List | 6.7.11 | unaffected |
| 6.6.23 | unaffected | ||
KernelBrowse Linux / Kernel | OSV | 6.6.0 to < 6.6.23 · Fixed in 6.6.23 | affected |
| 6.7.0 to < 6.7.11 · Fixed in 6.7.11 | affected | ||
| 6.8.0 to < 6.8.2 · Fixed in 6.8.2 | affected |