Arbitrary Memory read in BPF Linux Kernel
Published Sep 23, 2022
6.7
MEDIUMCVSS 3.1
EPSS 0.27%
Description
There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passed in to bpf_sys_bpf are not verified and can point anywhere, including memory not owned by BPF. An attacker with CAP_BPF can arbitrarily read memory from anywhere on the system. We recommend upgrading past commit 86f44fcec22c
Affected products
-
- Version 5.14StatusaffectedConstraints<af2ac3e13e45
- Version 5.18StatusaffectedConstraints<b1d18a7574d0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux Kernel | Kernel | n/a |
|
- < 5.19.4
No data.
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The default Red Hat Enterprise Linux kernel prevents unprivileged users from being able to use eBPF by the kernel.unprivileged_bpf_disabled sysctl. This would require a privileged user with CAP_SYS_ADMIN or root to be able to abuse this flaw reducing its attack space. For the Red Hat Enterprise Linux 7 the eBPF for unprivileged users is always disabled. For the Red Hat Enterprise Linux 8 to confirm the current state, inspect the sysctl with the command: ~~~ # cat /proc/sys/kernel/unprivileged_bpf_disabled ~~~ The setting of 1 would mean that unprivileged users can not use eBPF, mitigating the flaw. A kernel update will be required to mitigate the flaw for the root or users with CAP_SYS_ADMIN capabilities.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (8)
- https://access.redhat.com/security/cve/CVE-2022-2785 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2129419 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35026 Advisory
- https://git.kernel.org/bpf/bpf/c/86f44fcec22c x_refsource_MISCPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=86f44fcec22c
- https://lore.kernel.org/bpf/20220816205517.682470-1-zhuyifei%40google.com/T/#t x_refsource_MISCVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-2785
- https://www.cve.org/CVERecord?id=CVE-2022-2785
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-2785 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2129419 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-35026 | Advisory | |
| https://git.kernel.org/bpf/bpf/c/86f44fcec22c | x_refsource_MISCPatchVendor Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=86f44fcec22c | ||
| https://lore.kernel.org/bpf/20220816205517.682470-1-zhuyifei%40google.com/T/#t | x_refsource_MISCVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-2785 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2785 |
Change history (0)
No recorded changes yet.