REDHAT-BUG-2311717: Medium severity red hat kernel-devel vulnerability
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix a kernel verifier crash in stacksafe()
Daniel Hodges reported a kernel verifier crash when playing with sched-ext. Further investigation shows that the crash is due to invalid memory access in stacksafe(). More specifically, it is the following code:
if (exact != NOTEXACT && old->stack[spi].slottype[i % BPFREGSIZE] != cur->stack[spi].slottype[i % BPFREGSIZE]) return false;
The 'i' iterates old->allocatedstack. If cur->allocatedstack < old->allocatedstack the out-of-bound access will happen.
To fix the issue add 'i >= cur->allocatedstack' check such that if the condition is true, stacksafe() should fail. Otherwise, cur->stack[spi].slottype[i % BPFREGSIZE] memory access is legal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2311717?
The severity of REDHAT-BUG-2311717 is classified as high due to its potential to cause system crashes.
How do I fix REDHAT-BUG-2311717?
To fix REDHAT-BUG-2311717, update your Linux kernel to the latest patched version provided by Red Hat.
What systems are affected by REDHAT-BUG-2311717?
REDCAT-BUG-2311717 affects systems running specific versions of the Red Hat Kernel-devel.
What vulnerabilities does REDHAT-BUG-2311717 address?
REDCAT-BUG-2311717 addresses a kernel verifier crash due to invalid memory access in the stacksafe function.
Who reported the vulnerability REDHAT-BUG-2311717?
The vulnerability REDHAT-BUG-2311717 was reported by Daniel Hodges.