CVE-2024-35917: s390/bpf: Fix bpf_plt pointer arithmetic
In the Linux kernel, the following vulnerability has been resolved:
s390/bpf: Fix bpfplt pointer arithmetic
Kui-Feng Lee reported a crash on s390x triggered by the dummystops/dummyinitptrarg test [1]:
[<0000000000000002>] 0x2 [<00000000009d5cde>] bpfstructopstestrun+0x156/0x250 [<000000000033145a>] sysbpf+0xa1a/0xd00 [<00000000003319dc>] s390xsysbpf+0x44/0x50 [<0000000000c4382c>] dosyscall+0x244/0x300 [<0000000000c59a40>] systemcall+0x70/0x98
This is caused by GCC moving memcpy() after assignments in bpfjitplt(), resulting in NULL pointers being written instead of the return and the target addresses.
Looking at the GCC internals, the reordering is allowed because the alias analysis thinks that the memcpy() destination and the assignments' left-hand-sides are based on different objects: newplt and bpfpltret/bpfplttarget respectively, and therefore they cannot alias.
This is in turn due to a violation of the C standard:
When two pointers are subtracted, both shall point to elements of the same array object, or one past the last element of the array object ...
From the C's perspective, bpfpltret and bpfplt are distinct objects and cannot be subtracted. In the practical terms, doing so confuses the GCC's alias analysis.
The code was written this way in order to let the C side know a few offsets defined in the assembly. While nice, this is by no means necessary. Fix the noncompliance by hardcoding these offsets.
[1] https://lore.kernel.org/bpf/c9923c1d-971d-4022-8dc8-1364e929d34c@gmail.com/
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35917?
CVE-2024-35917 has a medium severity rating due to its potential to cause system crashes.
How do I fix CVE-2024-35917?
To resolve CVE-2024-35917, update the Linux kernel to one of the patched versions: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.11-1, or 6.12.12-1.
What types of systems are affected by CVE-2024-35917?
CVE-2024-35917 primarily affects Linux systems running on s390x architecture.
What components of the Linux kernel are impacted by CVE-2024-35917?
CVE-2024-35917 specifically affects the BPF (Berkeley Packet Filter) pointer arithmetic inside the Linux kernel.
Who reported the vulnerability CVE-2024-35917?
CVE-2024-35917 was reported by Kui-Feng Lee.