CVE-2024-45020: bpf: Fix a kernel verifier crash in stacksafe()
bpf: Fix a kernel verifier crash in stacksafe()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Patch bpf: Fix a kernel verifier crash in stacksafe()
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45020?
CVE-2024-45020 has been classified as a moderate severity vulnerability due to its potential to cause a kernel verifier crash.
How do I fix CVE-2024-45020?
To fix CVE-2024-45020, update the Linux kernel to a version that is not affected by this vulnerability, such as versions 5.10.223-1, 5.10.226-1, or 6.12.11-1.
Which versions of the Linux Kernel are affected by CVE-2024-45020?
CVE-2024-45020 affects Linux Kernel versions between 6.6.15 and 6.6.48, as well as versions between 6.7 and 6.10.7.
Who reported CVE-2024-45020?
CVE-2024-45020 was reported by Daniel Hodges following a kernel verifier crash.
What components are involved in the CVE-2024-45020 vulnerability?
The vulnerability involves a kernel verifier crash related to invalid memory access in the stacksafe() function.