CVE-2024-50138

MEDIUM

Linux Kernel 5.8-6.1.114, 6.2-6.6.83, 6.7-6.11.5 - Denial of Service via BPF Ringbuf Spinlock

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Use raw_spinlock_t in ringbuf The function __bpf_ringbuf_reserve is invoked from a tracepoint, which disables preemption. Using spinlock_t in this context can lead to a "sleep in atomic" warning in the RT variant. This issue is illustrated in the example below: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 556208, name: test_progs preempt_count: 1, expected: 0 RCU nest depth: 1, expected: 1 INFO: lockdep is turned off. Preemption disabled at: [<ffffd33a5c88ea44>] migrate_enable+0xc0/0x39c CPU: 7 PID: 556208 Comm: test_progs Tainted: G Hardware name: Qualcomm SA8775P Ride (DT) Call trace: dump_backtrace+0xac/0x130 show_stack+0x1c/0x30 dump_stack_lvl+0xac/0xe8 dump_stack+0x18/0x30 __might_resched+0x3bc/0x4fc rt_spin_lock+0x8c/0x1a4 __bpf_ringbuf_reserve+0xc4/0x254 bpf_ringbuf_reserve_dynptr+0x5c/0xdc bpf_prog_ac3d15160d62622a_test_read_write+0x104/0x238 trace_call_bpf+0x238/0x774 perf_call_bpf_enter.isra.0+0x104/0x194 perf_syscall_enter+0x2f8/0x510 trace_sys_enter+0x39c/0x564 syscall_trace_enter+0x220/0x3c0 do_el0_svc+0x138/0x1dc el0_svc+0x54/0x130 el0t_64_sync_handler+0x134/0x150 el0t_64_sync+0x17c/0x180 Switch the spinlock to raw_spinlock_t to avoid this error.

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (15)
linux/Kernel 5.8.0 - 6.1.115linux
linux/Kernel 6.2.0 - 6.6.84linux
linux/Kernel 6.7.0 - 6.11.6linux
Linux/Linux < 5.8
Linux/Linux 457f44363a8894135c85b7a9afd2bd8196db24ab - 5eb34999d118e69a20dc0c6556f315fcb0a1f8d3
Linux/Linux 457f44363a8894135c85b7a9afd2bd8196db24ab - 8b62645b09f870d70c7910e7550289d444239a46
Linux/Linux 457f44363a8894135c85b7a9afd2bd8196db24ab - ca30e682e5d6de44d12c4610767811c9a21d59ba
Linux/Linux 457f44363a8894135c85b7a9afd2bd8196db24ab - f9543375d9b150b2bcf16bb182e6b62309db0888
Linux/Linux 5.8
Linux/Linux 6.1.115 - 6.1.*
... and 5 more
Published Nov 05, 2024
Tracked Since Feb 18, 2026