PT-2024-6602 · Linux+1 · Linux Kernel+1

Zac Ecob

·

Published

2024-06-24

·

Updated

2025-09-29

·

CVE-2024-42072

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue is related to the may goto function in the Linux kernel's BPF (Berkeley Packet Filter) component. Two bugs were exposed by Zac's syzbot: the first bug is related to how may goto is patched when the offset is negative, and the second bug is in the verifier, which incorrectly prunes the exploration of the program when an actual infinite loop is detected. This can potentially allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-10855
BDU:2024-07749
CVE-2024-42072

Affected Products

Alt Linux
Linux Kernel