PT-2024-3334 · Linux+10 · Ebpf+11

Alvise De Faveri Tron

+3

·

Published

2024-04-08

·

Updated

2026-03-14

·

CVE-2024-2201

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel systems. This issue is related to a new variant of the Spectre v2 attack, called Native Branch History Injection (BHI), which can be used to leak arbitrary kernel memory at 3.5 kB/sec. The vulnerability can be exploited by an unauthenticated attacker to leak privileged memory, bypassing existing Spectre mitigation techniques.
Recommendations As a temporary workaround, consider disabling the eBPF functionality to minimize the risk of exploitation. Restrict access to the vulnerable InSpectre Gadget tool to prevent attackers from finding gadgets in the kernel. Apply the recommendations provided by Intel, including disabling non-privileged eBPF functionality, enabling enhanced speculation with indirect branch tracking (eIBRS), and enabling supervisor mode execution protection (SMEP). Add LFENCE instructions to specific places in the code to serve as serialization points and implement software sequences that clear the branch history buffer (BHB) for transitions between different security domains. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5101
ALSA-2024:5102
ALSA-2024:8617
BDU:2024-03598
CESA-2024_5101
CESA-2024_5102
CVE-2024-2201
DSA-5658-1
DSA-5836-1
INFSA-2024_5101
INFSA-2024_5102
INFSA-2024_8617
OPENSUSE-SU-2024:13853-1
OPENSUSE-SU-2024:13858-1
OPENSUSE-SU-2024_1259-1
OPENSUSE-SU-2024_1322-1
OPENSUSE-SU-2024_1322-2
OPENSUSE-SU-2024_1332-1
OPENSUSE-SU-2024_1332-2
OPENSUSE-SU-2024_1466-1
OPENSUSE-SU-2024_1480-1
OPENSUSE-SU-2024_1490-1
OPENSUSE-SU-2024_1540-1
OPENSUSE-SU-2024_1644-1
OPENSUSE-SU-2024_3423-1
OPENSUSE-SU-2025:14705-1
RHSA-2024:5101
RHSA-2024:5102
RHSA-2024:6994
RHSA-2024:6995
RHSA-2024:8613
RHSA-2024:8614
RHSA-2024:8617
RHSA-2024_5101
RHSA-2024_5102
RHSA-2024_8617
RLSA-2024:5101
RLSA-2024:5102
RLSA-2024:8617
RXSA-2024:5101
SUSE-SU-2024:1259-1
SUSE-SU-2024:1295-1
SUSE-SU-2024:1466-1
SUSE-SU-2024:1480-1
SUSE-SU-2024:1490-1
SUSE-SU-2024:1540-1
SUSE-SU-2024:1541-1
SUSE-SU-2024:1643-1
SUSE-SU-2024:1644-1
SUSE-SU-2024:1646-1
SUSE-SU-2024:1870-1
SUSE-SU-2024:2008-1
SUSE-SU-2024:2190-1
SUSE-SU-2024:2533-1
SUSE-SU-2024:2534-1
SUSE-SU-2024:2535-1
SUSE-SU-2024:3423-1
SUSE-SU-2024_2533-1
SUSE-SU-2024_2534-1
SUSE-SU-2024_3423-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1183-1
SUSE-SU-2025_1027-1
USN-6765-1
USN-6766-1
USN-6766-2
USN-6766-3
USN-6774-1
USN-6795-1
USN-6828-1
USN-6865-1
USN-6866-1
USN-6866-2
USN-6866-3
USN-6868-1
USN-6868-2

Affected Products

Almalinux
Astra Linux
Centos
Debian
Inspectre Gadget
Linuxmint
Linux Kernel
Red Hat
Rocky Linux
Suse
Ubuntu
Ebpf