bpf: Fix crash due to out of bounds access into reg2btf_ids.
Published Aug 22, 2024
6.7
MEDIUMCVSS 3.1
EPSS 0.21%
Description
When commit e6ac2450d6de ("bpf: Support bpf program calling kernel function") added kfunc support, it defined reg2btf_ids as a cheap way to translate the verifier reg type to the appropriate btf_vmlinux BTF ID, however commit c25b2ae13603 ("bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL") moved the __BPF_REG_TYPE_MAX from the last member of bpf_reg_type enum to after the base register types, and defined other variants using type flag composition. However, now, the direct usage of reg->type to index into reg2btf_ids may no longer fall into __BPF_REG_TYPE_MAX range, and hence lead to out of bounds access and kernel crash on dereference of bad pointer.
Affected products
-
Affected
- ≥ 5.16.11, < 5.16.12
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ 5.15.15 · < 5.15.37
- ≥ 5.16.1 · < 5.16.12
No data.
Red Hat Enterprise Linux 8.8 Extended Update Support
kernel-0:4.18.0-477.81.1.el8_8
Fixed · RHSA-2024:10262
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Affected
Red Hat Enterprise Linux 8
kernel-rt
Affected
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8.8 Extended Update Support | kernel-0:4.18.0-477.81.1.el8_8 | Fixed | RHSA-2024:10262 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2022-48929 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2307185 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-53808 Advisory
- https://git.kernel.org/stable/c/45ce4b4f9009102cd9f581196d480a59208690c1 Patch
- https://git.kernel.org/stable/c/8c39925e98d498b9531343066ef82ae39e41adae Patch
- https://git.kernel.org/stable/c/f0ce1bc9e0235dd7412240be493d7ea65ed9eadc Patch
- https://lore.kernel.org/linux-cve-announce/2024082222-CVE-2022-48929-857d@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2022-48929
- https://www.cve.org/CVERecord?id=CVE-2022-48929
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data