- Description
- In the Linux kernel, the following vulnerability has been resolved: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops When a BPF sock_ops program accesses ctx fields with dst_reg == src_reg, the SOCK_OPS_GET_SK() and SOCK_OPS_GET_FIELD() macros fail to zero the destination register in the !fullsock / !locked_tcp_sock path. Both macros borrow a temporary register to check is_fullsock / is_locked_tcp_sock when dst_reg == src_reg, because dst_reg holds the ctx pointer. When the check is false (e.g., TCP_NEW_SYN_RECV state with a request_sock), dst_reg should be zeroed but is not, leaving the stale ctx pointer: - SOCK_OPS_GET_SK: dst_reg retains the ctx pointer, passes NULL checks as PTR_TO_SOCKET_OR_NULL, and can be used as a bogus socket pointer, leading to stack-out-of-bounds access in helpers like bpf_skc_to_tcp6_sock(). - SOCK_OPS_GET_FIELD: dst_reg retains the ctx pointer which the verifier believes is a SCALAR_VALUE, leaking a kernel pointer. Fix both macros by: - Changing JMP_A(1) to JMP_A(2) in the fullsock path to skip the added instruction. - Adding BPF_MOV64_IMM(si->dst_reg, 0) after the temp register restore in the !fullsock path, placed after the restore because dst_reg == src_reg means we need src_reg intact to read ctx->temp.
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- NVD status
- Modified
- Products
- linux_kernel
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- nvd@nist.gov
- CWE-125
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "435DC924-B527-4D24-9771-05EBDC20047B",
"versionEndExcluding": "5.5",
"versionStartIncluding": "5.4.61",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8141C666-AECC-41B8-BD7E-DED92216B4A5",
"versionEndExcluding": "5.8",
"versionStartIncluding": "5.7.18",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "560FB3D4-80AB-415C-96DA-0097E0BCB36F",
"versionEndExcluding": "5.9",
"versionStartIncluding": "5.8.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9211326E-7B68-49D5-BDEC-B2289D9A2F81",
"versionEndExcluding": "7.0.10",
"versionStartIncluding": "5.9.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:-:*:*:*:*:*:*",
"matchCriteriaId": "F79A2EB6-623E-4749-AEE0-DCB58C4C42F8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc2:*:*:*:*:*:*",
"matchCriteriaId": "A67F6509-9592-44D5-8C65-B0791C7A501A",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc3:*:*:*:*:*:*",
"matchCriteriaId": "A52A4ABE-5C24-4CD4-A348-E303B7F23C71",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc4:*:*:*:*:*:*",
"matchCriteriaId": "12019CF2-FD8E-4D59-BA4C-7093DF0BB091",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc5:*:*:*:*:*:*",
"matchCriteriaId": "9B1AB90E-C0C6-4027-B27D-BA214BE33561",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc6:*:*:*:*:*:*",
"matchCriteriaId": "103FE5BA-7315-4263-9C95-EABEAD7E174F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc7:*:*:*:*:*:*",
"matchCriteriaId": "47E31D6A-31EC-4F63-9CAE-B7A52B58E149",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.9:rc8:*:*:*:*:*:*",
"matchCriteriaId": "3497462B-A3DA-47CC-A5DD-C1C2D2E6DFDE",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]