CVE-2024-26883 (GCVE-0-2024-26883)
Vulnerability from cvelistv5
Published
2024-04-17 10:27
Modified
2026-08-05 11:28
Summary
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stackmap overflow check on 32-bit arches The stackmap code relies on roundup_pow_of_two() to compute the number of hash buckets, and contains an overflow check by checking if the resulting value is 0. However, on 32-bit arches, the roundup code itself can overflow by doing a 32-bit left-shift of an unsigned long value, which is undefined behaviour, so it is not guaranteed to truncate neatly. This was triggered by syzbot on the DEVMAP_HASH type, which contains the same check, copied from the hashtab code. The commit in the fixes tag actually attempted to fix this, but the fix did not account for the UB, so the fix only works on CPUs where an overflow does result in a neat truncation to zero, which is not guaranteed. Checking the value before rounding does not have this problem.
Impacted products
Vendor Product Version
Linux Linux Version: 063c722dd9d285d877e6fd499e753d6224f4c046
Version: 7e3a6b820535eb395784060ae26c5af579528fa0
Version: 8032bf2af9ce26b3a362b9711d15f626ab946a74
Version: 6183f4d3a0a2ad230511987c6c362ca43ec0055f
Version: 6183f4d3a0a2ad230511987c6c362ca43ec0055f
Version: 6183f4d3a0a2ad230511987c6c362ca43ec0055f
Version: 6183f4d3a0a2ad230511987c6c362ca43ec0055f
Version: 6183f4d3a0a2ad230511987c6c362ca43ec0055f
Version: 6183f4d3a0a2ad230511987c6c362ca43ec0055f
Version: 253150830a012adfccf90afcebae8fda5b05a80f
Version: 766107351731ae223ebf60ca22bdfeb47ce6acc8
Version: 4.19.177   
Version: 5.4.99   
Version: 5.10.17   
Version: 4.9.258   
Version: 4.14.222   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:21:05.381Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/d0e214acc59145ce25113f617311aa79dda39cb3"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/21e5fa4688e1a4d3db6b72216231b24232f75c1d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/15641007df0f0d35fa28742b25c2a7db9dcd6895"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/ca1f06e72dec41ae4f76e7b1a8a97265447b46ae"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/f06899582ccee09bd85d0696290e3eaca9aa042d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/7070b274c7866a4c5036f8d54fcaf315c64ac33a"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/43f798b9036491fb014b55dd61c4c5c3193267d0"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/0971126c8164abe2004b8536b49690a0d6005b0a"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/7a4b21250bf79eef26543d35bd390448646c536b"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-26883",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T15:48:22.381696Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:25.228Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-12T11:50:06.933Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "kernel/bpf/stackmap.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "d0e214acc59145ce25113f617311aa79dda39cb3",
              "status": "affected",
              "version": "063c722dd9d285d877e6fd499e753d6224f4c046",
              "versionType": "git"
            },
            {
              "lessThan": "21e5fa4688e1a4d3db6b72216231b24232f75c1d",
              "status": "affected",
              "version": "7e3a6b820535eb395784060ae26c5af579528fa0",
              "versionType": "git"
            },
            {
              "lessThan": "15641007df0f0d35fa28742b25c2a7db9dcd6895",
              "status": "affected",
              "version": "8032bf2af9ce26b3a362b9711d15f626ab946a74",
              "versionType": "git"
            },
            {
              "lessThan": "ca1f06e72dec41ae4f76e7b1a8a97265447b46ae",
              "status": "affected",
              "version": "6183f4d3a0a2ad230511987c6c362ca43ec0055f",
              "versionType": "git"
            },
            {
              "lessThan": "f06899582ccee09bd85d0696290e3eaca9aa042d",
              "status": "affected",
              "version": "6183f4d3a0a2ad230511987c6c362ca43ec0055f",
              "versionType": "git"
            },
            {
              "lessThan": "7070b274c7866a4c5036f8d54fcaf315c64ac33a",
              "status": "affected",
              "version": "6183f4d3a0a2ad230511987c6c362ca43ec0055f",
              "versionType": "git"
            },
            {
              "lessThan": "43f798b9036491fb014b55dd61c4c5c3193267d0",
              "status": "affected",
              "version": "6183f4d3a0a2ad230511987c6c362ca43ec0055f",
              "versionType": "git"
            },
            {
              "lessThan": "0971126c8164abe2004b8536b49690a0d6005b0a",
              "status": "affected",
              "version": "6183f4d3a0a2ad230511987c6c362ca43ec0055f",
              "versionType": "git"
            },
            {
              "lessThan": "7a4b21250bf79eef26543d35bd390448646c536b",
              "status": "affected",
              "version": "6183f4d3a0a2ad230511987c6c362ca43ec0055f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "253150830a012adfccf90afcebae8fda5b05a80f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "766107351731ae223ebf60ca22bdfeb47ce6acc8",
              "versionType": "git"
            },
            {
              "lessThan": "4.19.311",
              "status": "affected",
              "version": "4.19.177",
              "versionType": "semver"
            },
            {
              "lessThan": "5.4.273",
              "status": "affected",
              "version": "5.4.99",
              "versionType": "semver"
            },
            {
              "lessThan": "5.10.214",
              "status": "affected",
              "version": "5.10.17",
              "versionType": "semver"
            },
            {
              "lessThan": "4.10",
              "status": "affected",
              "version": "4.9.258",
              "versionType": "semver"
            },
            {
              "lessThan": "4.15",
              "status": "affected",
              "version": "4.14.222",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "kernel/bpf/stackmap.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.11"
            },
            {
              "lessThan": "5.11",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.311",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.273",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.214",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.153",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.83",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.23",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.311",
                  "versionStartIncluding": "4.19.177",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.273",
                  "versionStartIncluding": "5.4.99",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.214",
                  "versionStartIncluding": "5.10.17",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.153",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.83",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.23",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.11",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.2",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "5.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.9.258",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "4.14.222",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix stackmap overflow check on 32-bit arches\n\nThe stackmap code relies on roundup_pow_of_two() to compute the number\nof hash buckets, and contains an overflow check by checking if the\nresulting value is 0. However, on 32-bit arches, the roundup code itself\ncan overflow by doing a 32-bit left-shift of an unsigned long value,\nwhich is undefined behaviour, so it is not guaranteed to truncate\nneatly. This was triggered by syzbot on the DEVMAP_HASH type, which\ncontains the same check, copied from the hashtab code.\n\nThe commit in the fixes tag actually attempted to fix this, but the fix\ndid not account for the UB, so the fix only works on CPUs where an\noverflow does result in a neat truncation to zero, which is not\nguaranteed. Checking the value before rounding does not have this\nproblem."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached solely through the bpf(BPF_MAP_CREATE) syscall from a local process; no network or remote peer data is involved in stackmap creation.\nAC:L - A single syscall with max_entries \u003e 0x80000000 deterministically bypasses the overflow check on a 32-bit kernel \u2014 no race, no memory-layout precondition, and the attacker fully controls max_entries and value_size (hence the OOB write stride).\nPR:L - Creating a BPF_MAP_TYPE_STACK_TRACE map requires CAP_BPF (bpf_capable()/bpf_token_capable()), a delegated capability routinely granted to unprivileged observability agents, container runtimes and BPF-token-holding workloads rather than full root.\nUI:N - The attacker triggers the entire flaw with its own syscall; no victim action, mount, or file open is needed.\nS:U - The corruption is confined to kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The truncated allocation leaves pcpu_freelist nodes pointing into arbitrary kernel memory, which subsequent bpf_get_stackid()/map lookups copy back to userspace, and the resulting heap corruption is generally leverageable for arbitrary kernel memory disclosure.\nI:H - pcpu_freelist_populate() performs ~2^31 pointer writes at an attacker-chosen stride past a tiny (attacker-sized) allocation, an unbounded out-of-bounds write of kernel pointer values that is exploitable for control-flow hijacking.\nA:H - The wild writes sweep gigabytes of kernel address space and reliably corrupt slab metadata and unmapped pages, guaranteeing an oops/panic; even on trees where the write is avoided the path is a hard map-creation failure."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:28:08.431Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/d0e214acc59145ce25113f617311aa79dda39cb3"
        },
        {
          "url": "https://git.kernel.org/stable/c/21e5fa4688e1a4d3db6b72216231b24232f75c1d"
        },
        {
          "url": "https://git.kernel.org/stable/c/15641007df0f0d35fa28742b25c2a7db9dcd6895"
        },
        {
          "url": "https://git.kernel.org/stable/c/ca1f06e72dec41ae4f76e7b1a8a97265447b46ae"
        },
        {
          "url": "https://git.kernel.org/stable/c/f06899582ccee09bd85d0696290e3eaca9aa042d"
        },
        {
          "url": "https://git.kernel.org/stable/c/7070b274c7866a4c5036f8d54fcaf315c64ac33a"
        },
        {
          "url": "https://git.kernel.org/stable/c/43f798b9036491fb014b55dd61c4c5c3193267d0"
        },
        {
          "url": "https://git.kernel.org/stable/c/0971126c8164abe2004b8536b49690a0d6005b0a"
        },
        {
          "url": "https://git.kernel.org/stable/c/7a4b21250bf79eef26543d35bd390448646c536b"
        }
      ],
      "title": "bpf: Fix stackmap overflow check on 32-bit arches",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26883",
    "datePublished": "2024-04-17T10:27:39.036Z",
    "dateReserved": "2024-02-19T14:20:24.185Z",
    "dateUpdated": "2026-08-05T11:28:08.431Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d0e214acc59145ce25113f617311aa79dda39cb3\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/21e5fa4688e1a4d3db6b72216231b24232f75c1d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/15641007df0f0d35fa28742b25c2a7db9dcd6895\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/ca1f06e72dec41ae4f76e7b1a8a97265447b46ae\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/f06899582ccee09bd85d0696290e3eaca9aa042d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/7070b274c7866a4c5036f8d54fcaf315c64ac33a\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/43f798b9036491fb014b55dd61c4c5c3193267d0\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/0971126c8164abe2004b8536b49690a0d6005b0a\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/7a4b21250bf79eef26543d35bd390448646c536b\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:21:05.381Z\"}}, {\"affected\": [{\"vendor\": \"Siemens\", \"product\": \"SIMATIC S7-1500 TM MFP - GNU/Linux subsystem\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"lessThan\": \"*\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unknown\"}], \"x_adpType\": \"supplier\", \"references\": [{\"url\": \"https://cert-portal.siemens.com/productcert/html/ssa-265688.html\"}], \"providerMetadata\": {\"orgId\": \"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e\", \"shortName\": \"siemens-SADP\", \"dateUpdated\": \"2026-05-12T11:50:06.933Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26883\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T15:48:22.381696Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:16.599Z\"}}], \"cna\": {\"title\": \"bpf: Fix stackmap overflow check on 32-bit arches\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerability is reached solely through the bpf(BPF_MAP_CREATE) syscall from a local process; no network or remote peer data is involved in stackmap creation.\\nAC:L - A single syscall with max_entries \u003e 0x80000000 deterministically bypasses the overflow check on a 32-bit kernel \\u2014 no race, no memory-layout precondition, and the attacker fully controls max_entries and value_size (hence the OOB write stride).\\nPR:L - Creating a BPF_MAP_TYPE_STACK_TRACE map requires CAP_BPF (bpf_capable()/bpf_token_capable()), a delegated capability routinely granted to unprivileged observability agents, container runtimes and BPF-token-holding workloads rather than full root.\\nUI:N - The attacker triggers the entire flaw with its own syscall; no victim action, mount, or file open is needed.\\nS:U - The corruption is confined to kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\\nC:H - The truncated allocation leaves pcpu_freelist nodes pointing into arbitrary kernel memory, which subsequent bpf_get_stackid()/map lookups copy back to userspace, and the resulting heap corruption is generally leverageable for arbitrary kernel memory disclosure.\\nI:H - pcpu_freelist_populate() performs ~2^31 pointer writes at an attacker-chosen stride past a tiny (attacker-sized) allocation, an unbounded out-of-bounds write of kernel pointer values that is exploitable for control-flow hijacking.\\nA:H - The wild writes sweep gigabytes of kernel address space and reliably corrupt slab metadata and unmapped pages, guaranteeing an oops/panic; even on trees where the write is avoided the path is a hard map-creation failure.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"063c722dd9d285d877e6fd499e753d6224f4c046\", \"lessThan\": \"d0e214acc59145ce25113f617311aa79dda39cb3\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"7e3a6b820535eb395784060ae26c5af579528fa0\", \"lessThan\": \"21e5fa4688e1a4d3db6b72216231b24232f75c1d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"8032bf2af9ce26b3a362b9711d15f626ab946a74\", \"lessThan\": \"15641007df0f0d35fa28742b25c2a7db9dcd6895\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6183f4d3a0a2ad230511987c6c362ca43ec0055f\", \"lessThan\": \"ca1f06e72dec41ae4f76e7b1a8a97265447b46ae\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6183f4d3a0a2ad230511987c6c362ca43ec0055f\", \"lessThan\": \"f06899582ccee09bd85d0696290e3eaca9aa042d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6183f4d3a0a2ad230511987c6c362ca43ec0055f\", \"lessThan\": \"7070b274c7866a4c5036f8d54fcaf315c64ac33a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6183f4d3a0a2ad230511987c6c362ca43ec0055f\", \"lessThan\": \"43f798b9036491fb014b55dd61c4c5c3193267d0\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6183f4d3a0a2ad230511987c6c362ca43ec0055f\", \"lessThan\": \"0971126c8164abe2004b8536b49690a0d6005b0a\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"6183f4d3a0a2ad230511987c6c362ca43ec0055f\", \"lessThan\": \"7a4b21250bf79eef26543d35bd390448646c536b\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"253150830a012adfccf90afcebae8fda5b05a80f\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"766107351731ae223ebf60ca22bdfeb47ce6acc8\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"4.19.177\", \"lessThan\": \"4.19.311\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.4.99\", \"lessThan\": \"5.4.273\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"5.10.17\", \"lessThan\": \"5.10.214\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"4.9.258\", \"lessThan\": \"4.10\", \"versionType\": \"semver\"}, {\"status\": \"affected\", \"version\": \"4.14.222\", \"lessThan\": \"4.15\", \"versionType\": \"semver\"}], \"programFiles\": [\"kernel/bpf/stackmap.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.11\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.11\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.311\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.273\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.214\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.153\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.83\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.23\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"kernel/bpf/stackmap.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/d0e214acc59145ce25113f617311aa79dda39cb3\"}, {\"url\": \"https://git.kernel.org/stable/c/21e5fa4688e1a4d3db6b72216231b24232f75c1d\"}, {\"url\": \"https://git.kernel.org/stable/c/15641007df0f0d35fa28742b25c2a7db9dcd6895\"}, {\"url\": \"https://git.kernel.org/stable/c/ca1f06e72dec41ae4f76e7b1a8a97265447b46ae\"}, {\"url\": \"https://git.kernel.org/stable/c/f06899582ccee09bd85d0696290e3eaca9aa042d\"}, {\"url\": \"https://git.kernel.org/stable/c/7070b274c7866a4c5036f8d54fcaf315c64ac33a\"}, {\"url\": \"https://git.kernel.org/stable/c/43f798b9036491fb014b55dd61c4c5c3193267d0\"}, {\"url\": \"https://git.kernel.org/stable/c/0971126c8164abe2004b8536b49690a0d6005b0a\"}, {\"url\": \"https://git.kernel.org/stable/c/7a4b21250bf79eef26543d35bd390448646c536b\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nbpf: Fix stackmap overflow check on 32-bit arches\\n\\nThe stackmap code relies on roundup_pow_of_two() to compute the number\\nof hash buckets, and contains an overflow check by checking if the\\nresulting value is 0. However, on 32-bit arches, the roundup code itself\\ncan overflow by doing a 32-bit left-shift of an unsigned long value,\\nwhich is undefined behaviour, so it is not guaranteed to truncate\\nneatly. This was triggered by syzbot on the DEVMAP_HASH type, which\\ncontains the same check, copied from the hashtab code.\\n\\nThe commit in the fixes tag actually attempted to fix this, but the fix\\ndid not account for the UB, so the fix only works on CPUs where an\\noverflow does result in a neat truncation to zero, which is not\\nguaranteed. Checking the value before rounding does not have this\\nproblem.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.311\", \"versionStartIncluding\": \"4.19.177\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.273\", \"versionStartIncluding\": \"5.4.99\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.214\", \"versionStartIncluding\": \"5.10.17\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.153\", \"versionStartIncluding\": \"5.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.83\", \"versionStartIncluding\": \"5.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.23\", \"versionStartIncluding\": \"5.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.11\", \"versionStartIncluding\": \"5.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.2\", \"versionStartIncluding\": \"5.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"5.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"4.9.258\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionStartIncluding\": \"4.14.222\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:28:08.431Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26883\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:28:08.431Z\", \"dateReserved\": \"2024-02-19T14:20:24.185Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-17T10:27:39.036Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…