Back

HIGH

libbpf: Handle size overflow for ringbuf mmap

Published Oct 21, 2024

Description

The maximum size of ringbuf is 2GB on x86-64 host, so 2 * max_entries will overflow u32 when mapping producer page and data pages. Only casting max_entries to size_t is not enough, because for 32-bits application on 64-bits kernel the size of read-only mmap region also could overflow size_t.

So fixing it by casting the size of read-only mmap region into a __u64 and checking whether or not there will be overflow during mmap.

Affected products

Remediation

Red Hat statement

BPF is a privileged operation on RHEL Kernel.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026
Reserved Aug 22, 2024
CISA Vulnrichment
Updated Oct 22, 2024
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Low
Public date Oct 21, 2024
ENISA EUVD
Assigner Linux
Published Oct 21, 2024
Updated Aug 5, 2026
Exploited since n/a
EUVD-2022-53914