In the Linux kernel, the following vulnerability has been resolved: bpf: Fix may_goto with negative offset. Zac's syzbot crafted a bpf prog that exposed two bugs in may_goto. The 1st bug is the way…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix may_goto with negative offset. Zac's syzbot crafted a bpf prog that exposed two bugs in may_goto. The 1st bug is the way may_goto is patched. When offset is negative it should be patched differently. The 2nd bug is in the verifier: when current state may_goto_depth is equal to visited state may_goto_depth it means there is an actual infinite loop. It's not correct to prune exploration of the program at this point. No…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/175827e04f4be53f3dfb57edf12d0d49b18fd939 Patch
- https://git.kernel.org/stable/c/2b2efe1937ca9f8815884bd4dcd5b32733025103 Patch
- https://git.kernel.org/stable/c/175827e04f4be53f3dfb57edf12d0d49b18fd939 Patch
- https://git.kernel.org/stable/c/2b2efe1937ca9f8815884bd4dcd5b32733025103 Patch
Timeline
- nvd_ingest NVD