In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted v…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted via tail calls. Given two programs each utilizing a cgroup local storage with a different value size, and one program doing a tail call into the other. The verifier will validate each of the indivial programs just fine. However, in the runtime context the bpf_cg_run_ctx holds an bpf_prog_array_item w…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/19341d5c59e8c7e8528e40f8663e99d67810473c Patch
- https://git.kernel.org/stable/c/41688d1fc5d163a6c2c0e95c0419e2cb31a44648 Patch
- https://git.kernel.org/stable/c/66da7cee78590259b400e51a70622ccd41da7bb2 Patch
- https://git.kernel.org/stable/c/7acfa07c585e3d7a64654d38f0a5c762877d0b9b Patch
- https://git.kernel.org/stable/c/abad3d0bad72a52137e0c350c59542d75ae4f513 Patch
- https://git.kernel.org/stable/c/c1c74584b9b4043c52e41fec415226e582d266a3 Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Mailing List
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html Third Party Advisory
Timeline
- nvd_ingest NVD