PT-2025-19712 · Linux+4 · Linux Kernel+4

CVE-2024-58237

·

Published

2025-05-05

·

Updated

2026-05-26

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns the Linux kernel's bpf (Berkeley Packet Filter) functionality. Specifically, it involves tail calls that can invalidate packet pointers, potentially allowing tail-called programs to execute helpers that should not be accessible. This could lead to unsafe operations, such as modifying packet data after a tail call. The problem is addressed by conservatively assuming each tail call invalidates packet pointers, thus enhancing the security of bpf programs by rejecting those that could lead to unsafe conditions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-69932
BDU:2025-14125
CVE-2024-58237
ECHO-790D-47B6-0C62
OESA-2025-1878
OESA-2025-1879
OESA-2025-1880
OESA-2025-2554
OESA-2025-2555
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7513-1
USN-7513-2
USN-7513-3
USN-7513-4
USN-7513-5
USN-7514-1
USN-7515-1
USN-7515-2
USN-7522-1
USN-7523-1
USN-7524-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu