Back

MEDIUM

bpf: Fix crash due to out of bounds access into reg2btf_ids.

Published Aug 22, 2024

Description

When commit e6ac2450d6de ("bpf: Support bpf program calling kernel function") added kfunc support, it defined reg2btf_ids as a cheap way to translate the verifier reg type to the appropriate btf_vmlinux BTF ID, however commit c25b2ae13603 ("bpf: Replace PTR_TO_XXX_OR_NULL with PTR_TO_XXX | PTR_MAYBE_NULL") moved the __BPF_REG_TYPE_MAX from the last member of bpf_reg_type enum to after the base register types, and defined other variants using type flag composition. However, now, the direct usage of reg->type to index into reg2btf_ids may no longer fall into __BPF_REG_TYPE_MAX range, and hence lead to out of bounds access and kernel crash on dereference of bad pointer.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Aug 22, 2024
Updated May 11, 2026
Reserved Aug 21, 2024

CISA Vulnrichment

Updated Sep 10, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Aug 22, 2024
Bugzilla 2307185

ENISA EUVD

Assigner Linux
Published Aug 22, 2024
Updated May 11, 2026

GitHub

No data