CVE-2024-53099: bpf: Check validity of link->type in bpf_link_show_fdinfo()
bpf: Check validity of link->type in bpflinkshowfdinfo()
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.129-1~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-53099?
CVE-2024-53099 has been rated as a medium severity vulnerability.
How do I fix CVE-2024-53099?
To fix CVE-2024-53099, update your Linux kernel to version 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.15-1.
Which versions of the Linux kernel are affected by CVE-2024-53099?
CVE-2024-53099 affects Linux kernel versions from 6.7 to 6.11.9 and specific release candidates in version 6.12.
What is the nature of the vulnerability described in CVE-2024-53099?
CVE-2024-53099 involves an out-of-bounds access due to improper handling of a new link type in BPF.
Is CVE-2024-53099 exploitable?
Yes, CVE-2024-53099 is potentially exploitable, which could lead to a denial of service or code execution.