PT-2024-9379 · Linux+5 · Linux Kernel+5
Syzbot
·
Published
2024-06-05
·
Updated
2025-10-03
·
CVE-2024-40908
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The issue is related to the bpf component of the Linux kernel, specifically with the
bpf prog test run raw tp() function, which has an incorrect input validation. This can lead to a denial of service when a rawtp program is executed through the test run interface and calls the bpf get attach cookie helper or any other helper that touches the task->bpf ctx pointer. The problem arises when the test run callback is called without setting the run context, resulting in a crash.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu