CVE-2024-35860 (GCVE-0-2024-35860)
Vulnerability from cvelistv5
Published
2024-05-19 08:34
Modified
2026-08-05 11:30
Summary
In the Linux kernel, the following vulnerability has been resolved: bpf: support deferring bpf_link dealloc to after RCU grace period BPF link for some program types is passed as a "context" which can be used by those BPF programs to look up additional information. E.g., for multi-kprobes and multi-uprobes, link is used to fetch BPF cookie values. Because of this runtime dependency, when bpf_link refcnt drops to zero there could still be active BPF programs running accessing link data. This patch adds generic support to defer bpf_link dealloc callback to after RCU GP, if requested. This is done by exposing two different deallocation callbacks, one synchronous and one deferred. If deferred one is provided, bpf_link_free() will schedule dealloc_deferred() callback to happen after RCU GP. BPF is using two flavors of RCU: "classic" non-sleepable one and RCU tasks trace one. The latter is used when sleepable BPF programs are used. bpf_link_free() accommodates that by checking underlying BPF program's sleepable flag, and goes either through normal RCU GP only for non-sleepable, or through RCU tasks trace GP *and* then normal RCU GP (taking into account rcu_trace_implies_rcu_gp() optimization), if BPF program is sleepable. We use this for multi-kprobe and multi-uprobe links, which dereference link during program run. We also preventively switch raw_tp link to use deferred dealloc callback, as upcoming changes in bpf-next tree expose raw_tp link data (specifically, cookie value) to BPF program at runtime as well.
Impacted products
Vendor Product Version
Linux Linux Version: 0dcac272540613d41c05e89679e4ddb978b612f1
Version: 0dcac272540613d41c05e89679e4ddb978b612f1
Version: 0dcac272540613d41c05e89679e4ddb978b612f1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-02T03:21:48.532Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/876941f533e7b47fc69977fc4551c02f2d18af97"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/5d8d447777564b35f67000e7838e7ccb64d525c8"
          },
          {
            "tags": [
              "x_transferred"
            ],
            "url": "https://git.kernel.org/stable/c/1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-35860",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-09-10T15:41:33.868687Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-09-11T17:33:17.617Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "include/linux/bpf.h",
            "kernel/bpf/syscall.c",
            "kernel/trace/bpf_trace.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "876941f533e7b47fc69977fc4551c02f2d18af97",
              "status": "affected",
              "version": "0dcac272540613d41c05e89679e4ddb978b612f1",
              "versionType": "git"
            },
            {
              "lessThan": "5d8d447777564b35f67000e7838e7ccb64d525c8",
              "status": "affected",
              "version": "0dcac272540613d41c05e89679e4ddb978b612f1",
              "versionType": "git"
            },
            {
              "lessThan": "1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce",
              "status": "affected",
              "version": "0dcac272540613d41c05e89679e4ddb978b612f1",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "include/linux/bpf.h",
            "kernel/bpf/syscall.c",
            "kernel/trace/bpf_trace.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.18"
            },
            {
              "lessThan": "5.18",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.26",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.8.*",
              "status": "unaffected",
              "version": "6.8.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.9",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.26",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.8.5",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.9",
                  "versionStartIncluding": "5.18",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: support deferring bpf_link dealloc to after RCU grace period\n\nBPF link for some program types is passed as a \"context\" which can be\nused by those BPF programs to look up additional information. E.g., for\nmulti-kprobes and multi-uprobes, link is used to fetch BPF cookie values.\n\nBecause of this runtime dependency, when bpf_link refcnt drops to zero\nthere could still be active BPF programs running accessing link data.\n\nThis patch adds generic support to defer bpf_link dealloc callback to\nafter RCU GP, if requested. This is done by exposing two different\ndeallocation callbacks, one synchronous and one deferred. If deferred\none is provided, bpf_link_free() will schedule dealloc_deferred()\ncallback to happen after RCU GP.\n\nBPF is using two flavors of RCU: \"classic\" non-sleepable one and RCU\ntasks trace one. The latter is used when sleepable BPF programs are\nused. bpf_link_free() accommodates that by checking underlying BPF\nprogram\u0027s sleepable flag, and goes either through normal RCU GP only for\nnon-sleepable, or through RCU tasks trace GP *and* then normal RCU GP\n(taking into account rcu_trace_implies_rcu_gp() optimization), if BPF\nprogram is sleepable.\n\nWe use this for multi-kprobe and multi-uprobe links, which dereference\nlink during program run. We also preventively switch raw_tp link to use\ndeferred dealloc callback, as upcoming changes in bpf-next tree expose\nraw_tp link data (specifically, cookie value) to BPF program at runtime\nas well."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reached solely through the local `bpf()` syscall \u2014 `BPF_PROG_LOAD` plus `BPF_LINK_CREATE` for a kprobe_multi/uprobe_multi link, then closing the link fd while the probes fire. No network or remote-peer input is involved anywhere on the path.\nAC:L - The attacker controls both sides of the race: it picks which kernel/user functions are probed (including ones that block, so return-hooks fire arbitrarily late), drives them in a loop across all CPUs, and closes the link fd at will; three independent syzbot reproducers hit it in practice, so no condition outside attacker influence is required.\nPR:L - Creating these links needs CAP_BPF+CAP_PERFMON, which `bpf_token_capable()` grants at `ns_capable()` level to a delegated BPF token inside a container, and which ordinary non-root tracing/observability service accounts routinely hold \u2014 that is a low-privileged account, not administrative control of the host.\nUI:N - The whole sequence \u2014 load program, create link, trigger the probes, close the fd \u2014 happens inside the attacker\u0027s own process. No action by any other user or administrator is needed.\nS:U - The use-after-free and everything it corrupts stay inside the kernel\u0027s own memory and privilege domain; no hypervisor, IOMMU, or other security-authority boundary is crossed.\nC:H - `bpf_kprobe_multi_cookie()` bsearches the freed `addrs` array and returns `*cookie` from the freed `cookies` allocation directly to the running BPF program, which can exfiltrate it via a map \u2014 a read primitive over attacker-sprayed reclaimed slab, and the freed link is fully groomable.\nI:H - `kprobe_multi_link_prog_run()`/`uprobe_prog_run()` load `link-\u003elink.prog` out of freed memory and then indirect-call through it via `bpf_prog_run()`, and `fprobe_exit_handler()` calls `fp-\u003eexit_handler` from the same freed object \u2014 an attacker-controlled function-pointer dispatch giving control-flow hijack and full kernel-integrity compromise.\nA:H - Even without weaponization, dereferencing and calling through the freed link produces a KASAN slab-use-after-free splat and a wild indirect branch \u2014 an immediate oops or panic \u2014 and the attacker can repeat the create/trigger/close cycle indefinitely."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:30:24.039Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/876941f533e7b47fc69977fc4551c02f2d18af97"
        },
        {
          "url": "https://git.kernel.org/stable/c/5d8d447777564b35f67000e7838e7ccb64d525c8"
        },
        {
          "url": "https://git.kernel.org/stable/c/1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce"
        }
      ],
      "title": "bpf: support deferring bpf_link dealloc to after RCU grace period",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-35860",
    "datePublished": "2024-05-19T08:34:19.368Z",
    "dateReserved": "2024-05-17T13:50:33.107Z",
    "dateUpdated": "2026-08-05T11:30:24.039Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://git.kernel.org/stable/c/876941f533e7b47fc69977fc4551c02f2d18af97\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/5d8d447777564b35f67000e7838e7ccb64d525c8\", \"tags\": [\"x_transferred\"]}, {\"url\": \"https://git.kernel.org/stable/c/1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-02T03:21:48.532Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-35860\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-09-10T15:41:33.868687Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-09-11T12:42:15.967Z\"}}], \"cna\": {\"title\": \"bpf: support deferring bpf_link dealloc to after RCU grace period\", \"metrics\": [{\"cvssV3_1\": {\"version\": \"3.1\", \"baseScore\": 7.8, \"baseSeverity\": \"HIGH\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H\"}, \"scenarios\": [{\"lang\": \"en\", \"value\": \"AV:L - The vulnerability is reached solely through the local `bpf()` syscall \\u2014 `BPF_PROG_LOAD` plus `BPF_LINK_CREATE` for a kprobe_multi/uprobe_multi link, then closing the link fd while the probes fire. No network or remote-peer input is involved anywhere on the path.\\nAC:L - The attacker controls both sides of the race: it picks which kernel/user functions are probed (including ones that block, so return-hooks fire arbitrarily late), drives them in a loop across all CPUs, and closes the link fd at will; three independent syzbot reproducers hit it in practice, so no condition outside attacker influence is required.\\nPR:L - Creating these links needs CAP_BPF+CAP_PERFMON, which `bpf_token_capable()` grants at `ns_capable()` level to a delegated BPF token inside a container, and which ordinary non-root tracing/observability service accounts routinely hold \\u2014 that is a low-privileged account, not administrative control of the host.\\nUI:N - The whole sequence \\u2014 load program, create link, trigger the probes, close the fd \\u2014 happens inside the attacker\u0027s own process. No action by any other user or administrator is needed.\\nS:U - The use-after-free and everything it corrupts stay inside the kernel\u0027s own memory and privilege domain; no hypervisor, IOMMU, or other security-authority boundary is crossed.\\nC:H - `bpf_kprobe_multi_cookie()` bsearches the freed `addrs` array and returns `*cookie` from the freed `cookies` allocation directly to the running BPF program, which can exfiltrate it via a map \\u2014 a read primitive over attacker-sprayed reclaimed slab, and the freed link is fully groomable.\\nI:H - `kprobe_multi_link_prog_run()`/`uprobe_prog_run()` load `link-\u003elink.prog` out of freed memory and then indirect-call through it via `bpf_prog_run()`, and `fprobe_exit_handler()` calls `fp-\u003eexit_handler` from the same freed object \\u2014 an attacker-controlled function-pointer dispatch giving control-flow hijack and full kernel-integrity compromise.\\nA:H - Even without weaponization, dereferencing and calling through the freed link produces a KASAN slab-use-after-free splat and a wild indirect branch \\u2014 an immediate oops or panic \\u2014 and the attacker can repeat the create/trigger/close cycle indefinitely.\"}]}], \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"0dcac272540613d41c05e89679e4ddb978b612f1\", \"lessThan\": \"876941f533e7b47fc69977fc4551c02f2d18af97\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0dcac272540613d41c05e89679e4ddb978b612f1\", \"lessThan\": \"5d8d447777564b35f67000e7838e7ccb64d525c8\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"0dcac272540613d41c05e89679e4ddb978b612f1\", \"lessThan\": \"1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce\", \"versionType\": \"git\"}], \"programFiles\": [\"include/linux/bpf.h\", \"kernel/bpf/syscall.c\", \"kernel/trace/bpf_trace.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"5.18\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"5.18\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"6.6.26\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.8.5\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.8.*\"}, {\"status\": \"unaffected\", \"version\": \"6.9\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"include/linux/bpf.h\", \"kernel/bpf/syscall.c\", \"kernel/trace/bpf_trace.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/876941f533e7b47fc69977fc4551c02f2d18af97\"}, {\"url\": \"https://git.kernel.org/stable/c/5d8d447777564b35f67000e7838e7ccb64d525c8\"}, {\"url\": \"https://git.kernel.org/stable/c/1a80dbcb2dbaf6e4c216e62e30fa7d3daa8001ce\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nbpf: support deferring bpf_link dealloc to after RCU grace period\\n\\nBPF link for some program types is passed as a \\\"context\\\" which can be\\nused by those BPF programs to look up additional information. E.g., for\\nmulti-kprobes and multi-uprobes, link is used to fetch BPF cookie values.\\n\\nBecause of this runtime dependency, when bpf_link refcnt drops to zero\\nthere could still be active BPF programs running accessing link data.\\n\\nThis patch adds generic support to defer bpf_link dealloc callback to\\nafter RCU GP, if requested. This is done by exposing two different\\ndeallocation callbacks, one synchronous and one deferred. If deferred\\none is provided, bpf_link_free() will schedule dealloc_deferred()\\ncallback to happen after RCU GP.\\n\\nBPF is using two flavors of RCU: \\\"classic\\\" non-sleepable one and RCU\\ntasks trace one. The latter is used when sleepable BPF programs are\\nused. bpf_link_free() accommodates that by checking underlying BPF\\nprogram\u0027s sleepable flag, and goes either through normal RCU GP only for\\nnon-sleepable, or through RCU tasks trace GP *and* then normal RCU GP\\n(taking into account rcu_trace_implies_rcu_gp() optimization), if BPF\\nprogram is sleepable.\\n\\nWe use this for multi-kprobe and multi-uprobe links, which dereference\\nlink during program run. We also preventively switch raw_tp link to use\\ndeferred dealloc callback, as upcoming changes in bpf-next tree expose\\nraw_tp link data (specifically, cookie value) to BPF program at runtime\\nas well.\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.26\", \"versionStartIncluding\": \"5.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.8.5\", \"versionStartIncluding\": \"5.18\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.9\", \"versionStartIncluding\": \"5.18\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-08-05T11:30:24.039Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-35860\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-08-05T11:30:24.039Z\", \"dateReserved\": \"2024-05-17T13:50:33.107Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-05-19T08:34:19.368Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…