PT-2025-19711 · Linux+3 · Linux Kernel+3
Published
2025-05-05
·
Updated
2026-04-20
·
CVE-2024-58100
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue concerns the Linux kernel's handling of extension programs in relation to the
changes pkt data property. When processing calls to global sub-programs, the verifier decides whether to invalidate all packet pointers in the current state based on this property. An extension program replacing a global sub-program must be compatible with the changes pkt data property of the sub-program being replaced. The commit adds a changes pkt data flag to struct bpf prog aux and modifies bpf check attach btf id() to check this flag. The call to check attach btf id() is moved after the call to check cfg() because it needs the changes pkt data flag to be set.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linux Kernel
Suse