PT-2024-6602 · Linux+1 · Linux Kernel+1
Zac Ecob
·
Published
2024-06-24
·
Updated
2025-09-29
·
CVE-2024-42072
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue is related to the
may goto function in the Linux kernel's BPF (Berkeley Packet Filter) component. Two bugs were exposed by Zac's syzbot: the first bug is related to how may goto is patched when the offset is negative, and the second bug is in the verifier, which incorrectly prunes the exploration of the program when an actual infinite loop is detected. This can potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel