{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2024-50161", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2024-10-21T19:36:19.961Z", "datePublished": "2024-11-07T09:31:38.118Z", "dateUpdated": "2026-08-05T11:42:10.527Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:42:10.527Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check the remaining info_cnt before repeating btf fields\n\nWhen trying to repeat the btf fields for array of nested struct, it\ndoesn't check the remaining info_cnt. The following splat will be\nreported when the value of ret * nelems is greater than BTF_FIELDS_MAX:\n\n ------------[ cut here ]------------\n UBSAN: array-index-out-of-bounds in ../kernel/bpf/btf.c:3951:49\n index 11 is out of range for type 'btf_field_info [11]'\n CPU: 6 UID: 0 PID: 411 Comm: test_progs ...... 6.11.0-rc4+ #1\n Tainted: [O]=OOT_MODULE\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS ...\n Call Trace:\n \n dump_stack_lvl+0x57/0x70\n dump_stack+0x10/0x20\n ubsan_epilogue+0x9/0x40\n __ubsan_handle_out_of_bounds+0x6f/0x80\n ? kallsyms_lookup_name+0x48/0xb0\n btf_parse_fields+0x992/0xce0\n map_create+0x591/0x770\n __sys_bpf+0x229/0x2410\n __x64_sys_bpf+0x1f/0x30\n x64_sys_call+0x199/0x9f0\n do_syscall_64+0x3b/0xc0\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n RIP: 0033:0x7fea56f2cc5d\n ......\n \n ---[ end trace ]---\n\nFix it by checking the remaining info_cnt in btf_repeat_fields() before\nrepeating the btf fields." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The overflow is reached only through the local `bpf()` syscall — `BPF_MAP_CREATE` with an attacker-supplied BTF fd (`map_check_btf` → `btf_parse_fields`) or `BPF_PROG_LOAD` via `btf_parse_struct_metas()`. No network, adjacent, or physical path reaches BTF field parsing.\nAC:L - The attacker crafts the entire BTF blob offline — an array of `nelems` nested structs each holding a kptr/list_head — and the OOB write fires deterministically on the first syscall with no race to win and no condition outside the attacker's control. `nelems` directly selects how far past the 11-entry buffer the `memcpy` runs, so the attacker chooses between a precise caller-frame overwrite and a stack-destroying blowout.\nPR:L - `BPF_BTF_LOAD` and privileged map types gate on `bpf_token_capable(token, CAP_BPF)`, which falls back to `ns_capable(token->userns, CAP_BPF)` — so an unprivileged process holding a delegated BPF token, the mechanism built expressly for containers, reaches this path, and CAP_BPF is routinely granted to non-root observability/networking agents rather than being init-namespace root. Consistent with kernel CNA precedent for CAP_BPF-gated bugs (CVE-2025-21867, CVE-2024-53099), Low is the appropriate and higher-severity choice.\nUI:N - The attacker performs every step inside its own process — load the crafted BTF, then issue `BPF_MAP_CREATE` or `BPF_PROG_LOAD`. No victim action, mount, privileged helper, or file open is involved.\nS:U - The corrupted kernel stack and any resulting code execution stay within the kernel of the running system, the same security authority that manages the attacking process. No hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The corrupted `btf_field_info` slots are read straight back by `btf_parse_fields`, and `btf_parse_graph_root()` dereferences `info->graph_root.node_name` through `strcmp()`, turning an attacker-influenced stack slot into an arbitrary kernel-pointer read. More broadly, a controlled-length stack overflow into live caller frames is leverageable for arbitrary kernel memory disclosure.\nI:H - This is a genuine out-of-bounds write past a 264-byte kernel-stack buffer, with attacker-chosen length and semi-controlled 24-byte payloads containing attacker-supplied u32 offsets/type-ids and real kernel pointers. It overwrites saved registers, return addresses, and live caller-frame pointers (`map`, `btf`, `token`, `rec`) that are subsequently dereferenced and freed, yielding a control-flow-hijack / arbitrary-write primitive — and on builds without CONFIG_STACKPROTECTOR, direct return-address control.\nA:H - Even the minimal reported case corrupts the kernel stack (caught only incidentally by UBSAN), and since `nelems` is bounded only by `nelems * elem_size <= U32_MAX` the write can run hundreds of megabytes past the buffer, guaranteeing a stack-protector panic or guard-page fault. Any local caller with the required token can trigger this repeatedly for immediate, reliable denial of service." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "kernel/bpf/btf.c" ], "versions": [ { "version": "64e8ee814819f21beeeda00d4119221443d77992", "lessThan": "6f957d972feee9b385ea3ae6530310a84e55ba71", "status": "affected", "versionType": "git" }, { "version": "64e8ee814819f21beeeda00d4119221443d77992", "lessThan": "797d73ee232dd1833dec4824bc53a22032e97c1c", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "kernel/bpf/btf.c" ], "versions": [ { "version": "6.11", "status": "affected" }, { "version": "0", "lessThan": "6.11", "status": "unaffected", "versionType": "semver" }, { "version": "6.11.6", "lessThanOrEqual": "6.11.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.11", "versionEndExcluding": "6.11.6" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.11", "versionEndExcluding": "6.12" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/6f957d972feee9b385ea3ae6530310a84e55ba71" }, { "url": "https://git.kernel.org/stable/c/797d73ee232dd1833dec4824bc53a22032e97c1c" } ], "title": "bpf: Check the remaining info_cnt before repeating btf fields", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "metrics": [ { "cvssV3_1": { "scope": "UNCHANGED", "version": "3.1", "baseScore": 5.5, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "NONE" } }, { "other": { "type": "ssvc", "content": { "id": "CVE-2024-50161", "role": "CISA Coordinator", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "version": "2.0.3", "timestamp": "2025-10-01T20:20:20.703840Z" } } } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "type": "CWE", "cweId": "CWE-129", "description": "CWE-129 Improper Validation of Array Index" } ] } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-10-01T20:27:12.187Z" } } ] } }