CVE-2024-56665

MEDIUM

Linux Kernel 5.15.170-5.15.x - Use-After-Free in BPF Program Detachment

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog Syzbot reported [1] crash that happens for following tracing scenario: - create tracepoint perf event with attr.inherit=1, attach it to the process and set bpf program to it - attached process forks -> chid creates inherited event the new child event shares the parent's bpf program and tp_event (hence prog_array) which is global for tracepoint - exit both process and its child -> release both events - first perf_event_detach_bpf_prog call will release tp_event->prog_array and second perf_event_detach_bpf_prog will crash, because tp_event->prog_array is NULL The fix makes sure the perf_event_detach_bpf_prog checks prog_array is valid before it tries to remove the bpf program from it. [1] https://lore.kernel.org/bpf/Z1MR6dCIKajNS6nU@krava/T/#m91dbf0688221ec7a7fc95e896a7ef9ff93b0b8ad

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 12.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (21)
linux/Kernel < 6.1.121linux
linux/Kernel 6.2.0 - 6.6.67linux
linux/Kernel 6.7.0 - 6.12.6linux
Linux/Linux < 6.12
Linux/Linux 0ee288e69d033850bc87abe0f9cc3ada24763d7f - 978c4486cca5c7b9253d3ab98a88c8e769cb9bbd
Linux/Linux 0ee288e69d033850bc87abe0f9cc3ada24763d7f - dfb15ddf3b65e0df2129f9756d1b4fa78055cdb3
Linux/Linux 21db2f35fa97e4a3447f2edeb7b2569a8bfdc83b - c2b6b47662d5f2dfce92e5ffbdcac8229f321d9d
Linux/Linux 5.15.170 - 5.16
Linux/Linux 585674b9d0d80bd7f428b1f88be13cf6d5d6f739
Linux/Linux 6.1.115 - 6.1.121
... and 11 more
Published Dec 27, 2024
Tracked Since Feb 18, 2026