PT-2025-19712 · Linux+4 · Linux Kernel+4
CVE-2024-58237
·
Published
2025-05-05
·
Updated
2026-05-26
CVSS v2.0
7.7
High
| Vector | AV:A/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue concerns the Linux kernel's bpf (Berkeley Packet Filter) functionality. Specifically, it involves tail calls that can invalidate packet pointers, potentially allowing tail-called programs to execute helpers that should not be accessible. This could lead to unsafe operations, such as modifying packet data after a tail call. The problem is addressed by conservatively assuming each tail call invalidates packet pointers, thus enhancing the security of bpf programs by rejecting those that could lead to unsafe conditions.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu