CVE-2024-43910: bpf: add missing check_func_arg_reg_off() to prevent out-of-bounds memory accesses

Published Aug 26, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

bpf: add missing checkfuncargregoff() to prevent out-of-bounds memory accesses

Currently, it's possible to pass in a modified CONSTPTRTODYNPTR to a global function as an argument. The adverse effects of this is that BPF helpers can continue to make use of this modified CONSTPTRTODYNPTR from within the context of the global function, which can unintentionally result in out-of-bounds memory accesses and therefore compromise overall system stability i.e.

[ 244.157771] BUG: KASAN: slab-out-of-bounds in bpfdynptrdata+0x137/0x140 [ 244.161345] Read of size 8 at addr ffff88810914be68 by task testprogs/302 [ 244.167151] CPU: 0 PID: 302 Comm: testprogs Tainted: G O E 6.10.0-rc3-00131-g66b586715063 #533 [ 244.174318] Call Trace: [ 244.175787] <TASK> [ 244.177356] dumpstacklvl+0x66/0xa0 [ 244.179531] printreport+0xce/0x670 [ 244.182314] ? virtaddrvalid+0x200/0x3e0 [ 244.184908] kasanreport+0xd7/0x110 [ 244.187408] ? bpfdynptrdata+0x137/0x140 [ 244.189714] ? bpfdynptrdata+0x137/0x140 [ 244.192020] bpfdynptrdata+0x137/0x140 [ 244.194264] bpfprogb02a02fdd2bdc5faglobalcallbpfdynptrdata+0x22/0x26 [ 244.198044] bpfprogb0fe7b9d7dc3abdecallbackadjustbpfdynptrregoff+0x1f/0x23 [ 244.202136] bpfuserringbufdrain+0x2c7/0x570 [ 244.204744] ? 0xffffffffc0009e58 [ 244.206593] ? pfxbpfuserringbufdrain+0x10/0x10 [ 244.209795] bpfprog33ab33f6a804ba2duserringbufcallbackconstptrtodynptrregoff+0x47/0x4b [ 244.215922] bpftrampoline6442502480+0x43/0xe3 [ 244.218691] x64sysprlimit64+0x9/0xf0 [ 244.220912] dosyscall64+0xc1/0x1d0 [ 244.223043] entrySYSCALL64afterhwframe+0x77/0x7f [ 244.226458] RIP: 0033:0x7ffa3eb8f059 [ 244.228582] Code: 08 89 e8 5b 5d c3 66 2e 0f 1f 84 00 00 00 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8f 1d 0d 00 f7 d8 64 89 01 48 [ 244.241307] RSP: 002b:00007ffa3e9c6eb8 EFLAGS: 00000206 ORIGRAX: 000000000000012e [ 244.246474] RAX: ffffffffffffffda RBX: 00007ffa3e9c7cdc RCX: 00007ffa3eb8f059 [ 244.250478] RDX: 00007ffa3eb162b4 RSI: 0000000000000000 RDI: 00007ffa3e9c7fb0 [ 244.255396] RBP: 00007ffa3e9c6ed0 R08: 00007ffa3e9c76c0 R09: 0000000000000000 [ 244.260195] R10: 0000000000000000 R11: 0000000000000206 R12: ffffffffffffff80 [ 244.264201] R13: 000000000000001c R14: 00007ffc5d6b4260 R15: 00007ffa3e1c7000 [ 244.268303] </TASK>

Add a checkfuncargregoff() to the path in which the BPF verifier verifies the arguments of global function arguments, specifically those which take an argument of type ARGPTRTODYNPTR | MEMRDONLY. Also, processdynptrfunc() doesn't appear to perform any explicit and strict type matching on the supplied register type, so let's also enforce that a register either type PTRTOSTACK or CONSTPTRTODYNPTR is by the caller.

Other sources

In the Linux kernel, the following vulnerability has been resolved:

bpf: add missing checkfuncargregoff() to prevent out-of-bounds memory accesses

Currently, it's possible to pass in a modified CONSTPTRTODYNPTR to a global function as an argument. The adverse effects of this is that BPF helpers can continue to make use of this modified CONSTPTRTODYNPTR from within the context of the global function, which can unintentionally result in out-of-bounds memory accesses and therefore compromise overall system stability i.e.

[ 244.157771] BUG: KASAN: slab-out-of-bounds in bpfdynptrdata+0x137/0x140 [ 244.161345] Read of size 8 at addr ffff88810914be68 by task testprogs/302 [ 244.167151] CPU: 0 PID: 302 Comm: testprogs Tainted: G O E 6.10.0-rc3-00131-g66b586715063 #533 [ 244.174318] Call Trace: [ 244.175787] <TASK> [ 244.177356] dumpstacklvl+0x66/0xa0 [ 244.179531] printreport+0xce/0x670 [ 244.182314] ? virtaddrvalid+0x200/0x3e0 [ 244.184908] kasanreport+0xd7/0x110 [ 244.187408] ? bpfdynptrdata+0x137/0x140 [ 244.189714] ? bpfdynptrdata+0x137/0x140 [ 244.192020] bpfdynptrdata+0x137/0x140 [ 244.194264] bpfprogb02a02fdd2bdc5faglobalcallbpfdynptrdata+0x22/0x26 [ 244.198044] bpfprogb0fe7b9d7dc3abdecallbackadjustbpfdynptrregoff+0x1f/0x23 [ 244.202136] bpfuserringbufdrain+0x2c7/0x570 [ 244.204744] ? 0xffffffffc0009e58 [ 244.206593] ? pfxbpfuserringbufdrain+0x10/0x10 [ 244.209795] bpfprog33ab33f6a804ba2duserringbufcallbackconstptrtodynptrregoff+0x47/0x4b [ 244.215922] bpftrampoline6442502480+0x43/0xe3 [ 244.218691] x64sysprlimit64+0x9/0xf0 [ 244.220912] dosyscall64+0xc1/0x1d0 [ 244.223043] entrySYSCALL64afterhwframe+0x77/0x7f [ 244.226458] RIP: 0033:0x7ffa3eb8f059 [ 244.228582] Code: 08 89 e8 5b 5d c3 66 2e 0f 1f 84 00 00 00 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 8f 1d 0d 00 f7 d8 64 89 01 48 [ 244.241307] RSP: 002b:00007ffa3e9c6eb8 EFLAGS: 00000206 ORIGRAX: 000000000000012e [ 244.246474] RAX: ffffffffffffffda RBX: 00007ffa3e9c7cdc RCX: 00007ffa3eb8f059 [ 244.250478] RDX: 00007ffa3eb162b4 RSI: 0000000000000000 RDI: 00007ffa3e9c7fb0 [ 244.255396] RBP: 00007ffa3e9c6ed0 R08: 00007ffa3e9c76c0 R09: 0000000000000000 [ 244.260195] R10: 0000000000000000 R11: 0000000000000206 R12: ffffffffffffff80 [ 244.264201] R13: 000000000000001c R14: 00007ffc5d6b4260 R15: 00007ffa3e1c7000 [ 244.268303] </TASK>

Add a checkfuncargregoff() to the path in which the BPF verifier verifies the arguments of global function arguments, specifically those which take an argument of type ARGPTRTODYNPTR | MEMRDONLY. Also, processdynptrfunc() doesn't appear to perform any explicit and strict type matching on the supplied register type, so let's also enforce that a register either type PTRTOSTACK or CONSTPTRTODYNPTR is by the caller.

NVD

Affected Software

2 affected componentsFixes available
Linux Linux kernel>=6.8<6.10.5
debian/linux
5.10.223-15.10.234-16.1.129-16.1.133-16.12.22-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.133-1Fixed in 6.12.22-1

Event History

Aug 26, 2024
CVE Published
via MITRE·10:11 AM
Data Sourced
via MITRE·10:11 AM
DescriptionSeverity
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·11:21 AM
DescriptionSeverityAffected Software
Jan 13, 2025
Data Sourced
via Ubuntu·06:30 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-43910?

CVE-2024-43910 has been classified with a severity rating that necessitates immediate attention due to potential out-of-bounds memory access risks.

2

How do I fix CVE-2024-43910?

To fix CVE-2024-43910, upgrade your Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.119-1, 6.12.9-1, or 6.12.10-1.

3

Which versions of the Linux kernel are affected by CVE-2024-43910?

CVE-2024-43910 affects Linux kernel versions prior to 6.10.5, particularly between versions 6.8 and 6.10.5.

4

What are the potential impacts of CVE-2024-43910?

The potential impacts of CVE-2024-43910 include exploitation that could lead to arbitrary code execution due to out-of-bounds memory accesses.

5

Is CVE-2024-43910 specific to certain Linux distributions?

CVE-2024-43910 is primarily associated with the Linux kernel but can affect various distributions that utilize vulnerable kernel versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203