CVE-2024-26884 (GCVE-0-2024-26884)
Vulnerability from cvelistv5
Published
2024-04-17 10:27
Modified
2026-08-05 11:28
Summary
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix hashtab overflow check on 32-bit arches The hashtab code relies on roundup_pow_of_two() to compute the number of hash buckets, and contains an overflow check by checking if the resulting value is 0. However, on 32-bit arches, the roundup code itself can overflow by doing a 32-bit left-shift of an unsigned long value, which is undefined behaviour, so it is not guaranteed to truncate neatly. This was triggered by syzbot on the DEVMAP_HASH type, which contains the same check, copied from the hashtab code. So apply the same fix to hashtab, by moving the overflow check to before the roundup.
Impacted products
Vendor Product Version
Linux Linux Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Version: daaf427c6ab392bedcd018e326b2ffa1e1110cd6
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 7.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "LOW",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2024-26884",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-30T19:28:25.440727Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "problemTypes": [
          {
            "descriptions": [
              {
                "cweId": "CWE-190",
                "description": "CWE-190 Integer Overflow or Wraparound",
                "lang": "en",
                "type": "CWE"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-30T19:29:01.146Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T00:21:05.540Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/33ec04cadb77605b71d9298311919303d390c4d5"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/92c81fbb3ed2e0dfc33a4183a67135e1ab566ace"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/64f00b4df0597590b199b62a37a165473bf658a6"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/3b08cfc65f07b1132c1979d73f014ae6e04de55d"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/a83fdaeaea3677b83a53f72ace2d73a19bcd6d93"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/8435f0961bf3dc65e204094349bd9aeaac1f8868"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/d817f0d34d927f2deb17dadbfe212c9a6a32ac3e"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/a6fa75b5096c0f9826a4fabe22d907b0a5bb1016"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/6787d916c2cf9850c97a0a3f73e08c43e7d973b1"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-12T11:50:08.157Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "kernel/bpf/hashtab.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "33ec04cadb77605b71d9298311919303d390c4d5",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            },
            {
              "lessThan": "92c81fbb3ed2e0dfc33a4183a67135e1ab566ace",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            },
            {
              "lessThan": "64f00b4df0597590b199b62a37a165473bf658a6",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            },
            {
              "lessThan": "3b08cfc65f07b1132c1979d73f014ae6e04de55d",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            },
            {
              "lessThan": "a83fdaeaea3677b83a53f72ace2d73a19bcd6d93",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            },
            {
              "lessThan": "8435f0961bf3dc65e204094349bd9aeaac1f8868",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            },
            {
              "lessThan": "d817f0d34d927f2deb17dadbfe212c9a6a32ac3e",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            },
            {
              "lessThan": "a6fa75b5096c0f9826a4fabe22d907b0a5bb1016",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            },
            {
              "lessThan": "6787d916c2cf9850c97a0a3f73e08c43e7d973b1",
              "status": "affected",
              "version": "daaf427c6ab392bedcd018e326b2ffa1e1110cd6",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "kernel/bpf/hashtab.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.19"
            },
            {
              "lessThan": "3.19",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.311",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.273",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.214",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.153",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.83",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.23",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.7.*",
              "status": "unaffected",
              "version": "6.7.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.311",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.273",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.214",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.153",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.83",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.23",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.7.11",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.2",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "3.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix hashtab overflow check on 32-bit arches\n\nThe hashtab code relies on roundup_pow_of_two() to compute the number of\nhash buckets, and contains an overflow check by checking if the\nresulting value is 0. However, on 32-bit arches, the roundup code itself\ncan overflow by doing a 32-bit left-shift of an unsigned long value,\nwhich is undefined behaviour, so it is not guaranteed to truncate\nneatly. This was triggered by syzbot on the DEVMAP_HASH type, which\ncontains the same check, copied from the hashtab code. So apply the same\nfix to hashtab, by moving the overflow check to before the roundup."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached purely through the bpf(2) syscall \u2014 BPF_MAP_CREATE with an oversized max_entries followed by BPF_MAP_UPDATE_ELEM. No network or physical access is involved.\nAC:L - Exploitation is fully deterministic: one map-create with max_entries \u003e 0x80000000 and one map-update, with no race, no timing window and no memory-layout condition outside the attacker\u0027s control. The 32-bit-arch requirement is a property of the target platform (ARM32/x86-32/MIPS32 dominate embedded, IoT, automotive and Android-era devices running these stable branches), not a condition the attacker must win.\nPR:L - BPF_MAP_TYPE_HASH/PERCPU_HASH/HASH_OF_MAPS sit in the explicitly \"unprivileged\" branch of map_create()\u0027s privilege switch, requiring no CAP_BPF; the only gate is sysctl_unprivileged_bpf_disabled, which defaults to 0 on the affected 4.19/5.4/5.10 branches and on any build without CONFIG_BPF_UNPRIV_DEFAULT_OFF. A plain local user account therefore suffices.\nUI:N - The attacker performs the entire sequence themselves via two syscalls; no victim action, mount, or file open is needed.\nS:U - The corruption and its effects are confined to kernel memory within the same security authority; no hypervisor, IOMMU or sandbox boundary is crossed.\nC:H - A bogus n_buckets that escapes the overflow check leaves htab-\u003ebuckets as a zero-sized ZERO_SIZE_PTR allocation while __select_bucket() indexes it with an unmasked, key-derived 32-bit offset, so lookups read and dereference attacker-chosen out-of-bounds kernel memory, yielding an arbitrary-read primitive.\nI:H - The same wild bucket pointer is written through by htab_lock_bucket() (raw_spinlock acquire) and hlist_nulls_add_head_rcu() during map update, giving an out-of-bounds write of kernel list pointers at an attacker-influenced offset \u2014 a corruption primitive suitable for control-flow hijack.\nA:H - The identical pattern was demonstrated by syzbot as a kernel crash on arm32, and even the benign UB outcome (n_buckets == 1 with a ~4-billion entry limit) forces unbounded hash-chain walks under a raw spinlock with IRQs disabled, producing hard lockups, RCU stalls and panics."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:28:09.509Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/33ec04cadb77605b71d9298311919303d390c4d5"
        },
        {
          "url": "https://git.kernel.org/stable/c/92c81fbb3ed2e0dfc33a4183a67135e1ab566ace"
        },
        {
          "url": "https://git.kernel.org/stable/c/64f00b4df0597590b199b62a37a165473bf658a6"
        },
        {
          "url": "https://git.kernel.org/stable/c/3b08cfc65f07b1132c1979d73f014ae6e04de55d"
        },
        {
          "url": "https://git.kernel.org/stable/c/a83fdaeaea3677b83a53f72ace2d73a19bcd6d93"
        },
        {
          "url": "https://git.kernel.org/stable/c/8435f0961bf3dc65e204094349bd9aeaac1f8868"
        },
        {
          "url": "https://git.kernel.org/stable/c/d817f0d34d927f2deb17dadbfe212c9a6a32ac3e"
        },
        {
          "url": "https://git.kernel.org/stable/c/a6fa75b5096c0f9826a4fabe22d907b0a5bb1016"
        },
        {
          "url": "https://git.kernel.org/stable/c/6787d916c2cf9850c97a0a3f73e08c43e7d973b1"
        }
      ],
      "title": "bpf: Fix hashtab overflow check on 32-bit arches",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-26884",
    "datePublished": "2024-04-17T10:27:39.672Z",
    "dateReserved": "2024-02-19T14:20:24.185Z",
    "dateUpdated": "2026-08-05T11:28:09.509Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/33ec04cadb77605b71d9298311919303d390c4d5\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/92c81fbb3ed2e0dfc33a4183a67135e1ab566ace\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/64f00b4df0597590b199b62a37a165473bf658a6\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/3b08cfc65f07b1132c1979d73f014ae6e04de55d\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/a83fdaeaea3677b83a53f72ace2d73a19bcd6d93\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/8435f0961bf3dc65e204094349bd9aeaac1f8868\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/d817f0d34d927f2deb17dadbfe212c9a6a32ac3e\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/a6fa75b5096c0f9826a4fabe22d907b0a5bb1016\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/6787d916c2cf9850c97a0a3f73e08c43e7d973b1\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T00:21:05.540Z\"}}, {\"affected\": [{\"vendor\": \"Siemens\", \"product\": \"SIMATIC S7-1500 TM MFP - GNU/Linux subsystem\", \"versions\": [{\"status\": \"affected\", \"version\": \"0\", \"lessThan\": \"*\", \"versionType\": \"custom\"}], \"defaultStatus\": \"unknown\"}], \"x_adpType\": \"supplier\", \"references\": [{\"url\": \"https://cert-portal.siemens.com/productcert/html/ssa-265688.html\"}], \"providerMetadata\": {\"orgId\": \"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e\", \"shortName\": \"siemens-SADP\", \"dateUpdated\": \"2026-05-12T11:50:08.157Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 7.8, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\", \"integrityImpact\": \"HIGH\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"HIGH\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-26884\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"total\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-30T19:28:25.440727Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-190\", \"description\": \"CWE-190 Integer Overflow or Wraparound\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-06-17T19:18:34.078Z\"}}], \"cna\": {\"title\": \"bpf: Fix hashtab overflow check on 32-bit arches\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerability is reached purely through the bpf(2) syscall \\u2014 BPF_MAP_CREATE with an oversized max_entries followed by BPF_MAP_UPDATE_ELEM. No network or physical access is involved.\\nAC:L - Exploitation is fully deterministic: one map-create with max_entries \u003e 0x80000000 and one map-update, with no race, no timing window and no memory-layout condition outside the attacker\u0027s control. The 32-bit-arch requirement is a property of the target platform (ARM32/x86-32/MIPS32 dominate embedded, IoT, automotive and Android-era devices running these stable branches), not a condition the attacker must win.\\nPR:L - BPF_MAP_TYPE_HASH/PERCPU_HASH/HASH_OF_MAPS sit in the explicitly \\\"unprivileged\\\" branch of map_create()\u0027s privilege switch, requiring no CAP_BPF; the only gate is sysctl_unprivileged_bpf_disabled, which defaults to 0 on the affected 4.19/5.4/5.10 branches and on any build without CONFIG_BPF_UNPRIV_DEFAULT_OFF. A plain local user account therefore suffices.\\nUI:N - The attacker performs the entire sequence themselves via two syscalls; no victim action, mount, or file open is needed.\\nS:U - The corruption and its effects are confined to kernel memory within the same security authority; no hypervisor, IOMMU or sandbox boundary is crossed.\\nC:H - A bogus n_buckets that escapes the overflow check leaves htab-\u003ebuckets as a zero-sized ZERO_SIZE_PTR allocation while __select_bucket() indexes it with an unmasked, key-derived 32-bit offset, so lookups read and dereference attacker-chosen out-of-bounds kernel memory, yielding an arbitrary-read primitive.\\nI:H - The same wild bucket pointer is written through by htab_lock_bucket() (raw_spinlock acquire) and hlist_nulls_add_head_rcu() during map update, giving an out-of-bounds write of kernel list pointers at an attacker-influenced offset \\u2014 a corruption primitive suitable for control-flow hijack.\\nA:H - The identical pattern was demonstrated by syzbot as a kernel crash on arm32, and even the benign UB outcome (n_buckets == 1 with a ~4-billion entry limit) forces unbounded hash-chain walks under a raw spinlock with IRQs disabled, producing hard lockups, RCU stalls and panics.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"33ec04cadb77605b71d9298311919303d390c4d5\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"92c81fbb3ed2e0dfc33a4183a67135e1ab566ace\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"64f00b4df0597590b199b62a37a165473bf658a6\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"3b08cfc65f07b1132c1979d73f014ae6e04de55d\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"a83fdaeaea3677b83a53f72ace2d73a19bcd6d93\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"8435f0961bf3dc65e204094349bd9aeaac1f8868\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"d817f0d34d927f2deb17dadbfe212c9a6a32ac3e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"a6fa75b5096c0f9826a4fabe22d907b0a5bb1016\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"daaf427c6ab392bedcd018e326b2ffa1e1110cd6\", \"lessThan\": \"6787d916c2cf9850c97a0a3f73e08c43e7d973b1\", \"versionType\": \"git\"}], \"programFiles\": [\"kernel/bpf/hashtab.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"3.19\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"3.19\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.311\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.273\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.214\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.153\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.83\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.23\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.7.11\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.7.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.2\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"kernel/bpf/hashtab.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/33ec04cadb77605b71d9298311919303d390c4d5\"}, {\"url\": \"https://git.kernel.org/stable/c/92c81fbb3ed2e0dfc33a4183a67135e1ab566ace\"}, {\"url\": \"https://git.kernel.org/stable/c/64f00b4df0597590b199b62a37a165473bf658a6\"}, {\"url\": \"https://git.kernel.org/stable/c/3b08cfc65f07b1132c1979d73f014ae6e04de55d\"}, {\"url\": \"https://git.kernel.org/stable/c/a83fdaeaea3677b83a53f72ace2d73a19bcd6d93\"}, {\"url\": \"https://git.kernel.org/stable/c/8435f0961bf3dc65e204094349bd9aeaac1f8868\"}, {\"url\": \"https://git.kernel.org/stable/c/d817f0d34d927f2deb17dadbfe212c9a6a32ac3e\"}, {\"url\": \"https://git.kernel.org/stable/c/a6fa75b5096c0f9826a4fabe22d907b0a5bb1016\"}, {\"url\": \"https://git.kernel.org/stable/c/6787d916c2cf9850c97a0a3f73e08c43e7d973b1\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nbpf: Fix hashtab overflow check on 32-bit arches\\n\\nThe hashtab code relies on roundup_pow_of_two() to compute the number of\\nhash buckets, and contains an overflow check by checking if the\\nresulting value is 0. However, on 32-bit arches, the roundup code itself\\ncan overflow by doing a 32-bit left-shift of an unsigned long value,\\nwhich is undefined behaviour, so it is not guaranteed to truncate\\nneatly. This was triggered by syzbot on the DEVMAP_HASH type, which\\ncontains the same check, copied from the hashtab code. So apply the same\\nfix to hashtab, by moving the overflow check to before the roundup.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.311\", \"versionStartIncluding\": \"3.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.273\", \"versionStartIncluding\": \"3.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.214\", \"versionStartIncluding\": \"3.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.153\", \"versionStartIncluding\": \"3.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.83\", \"versionStartIncluding\": \"3.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.23\", \"versionStartIncluding\": \"3.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.7.11\", \"versionStartIncluding\": \"3.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.2\", \"versionStartIncluding\": \"3.19\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"3.19\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:28:09.509Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-26884\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:28:09.509Z\", \"dateReserved\": \"2024-02-19T14:20:24.185Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-04-17T10:27:39.672Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…