PT-2025-19711 · Linux+3 · Linux Kernel+3

Published

2025-05-05

·

Updated

2026-04-20

·

CVE-2024-58100

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns the Linux kernel's handling of extension programs in relation to the changes pkt data property. When processing calls to global sub-programs, the verifier decides whether to invalidate all packet pointers in the current state based on this property. An extension program replacing a global sub-program must be compatible with the changes pkt data property of the sub-program being replaced. The commit adds a changes pkt data flag to struct bpf prog aux and modifies bpf check attach btf id() to check this flag. The call to check attach btf id() is moved after the call to check cfg() because it needs the changes pkt data flag to be set.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

AZL-69929
BDU:2025-14124
CVE-2024-58100
ECHO-2B1E-053E-92A9
OESA-2025-1625
OESA-2025-1629
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1

Affected Products

Astra Linux
Debian
Linux Kernel
Suse