CVE-2024-42239: bpf: Fail bpf_timer_cancel when callback is being cancelled
bpf: Fail bpftimercancel when callback is being cancelled
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.43.1-7
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42239?
CVE-2024-42239 has been assigned a medium severity level due to its nature affecting the scheduling of timer callbacks in the Linux kernel.
How do I fix CVE-2024-42239?
To address CVE-2024-42239, update your Linux kernel to the fixed versions 5.10.223-1, 5.10.226-1, or 6.12.11-1.
Which versions of the Linux kernel are affected by CVE-2024-42239?
CVE-2024-42239 affects Linux kernel versions from 5.15 to 6.6.41 and from 6.7 to 6.9.10.
What type of vulnerability is CVE-2024-42239?
CVE-2024-42239 is a synchronization issue in the BPF (Berkeley Packet Filter) subsystem of the Linux kernel.
Is CVE-2024-42239 a remote or local vulnerability?
CVE-2024-42239 is considered a local vulnerability, as it requires local access to exploit the timing issues in BPF timer callbacks.