CVE-2024-42068
HIGH severity · CVSS 7.8 · CWE-252
7.8CVSS HIGH
Summary
In the Linux kernel, the following vulnerability has been resolved: bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro() set_memory_ro() can fail, leaving memory unprotected. Check its return and take it into account as an error.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Official patch: https://git.kernel.org/stable/c/05412471beba313ecded95aa17b25fe84bb2551a ↗
Additional information
- NVD record
- https://git.kernel.org/stable/c/05412471beba313ecded95aa17b25fe84bb2551aPatch
- https://git.kernel.org/stable/c/7d2cc63eca0c993c99d18893214abf8f85d566d8Patch
- https://git.kernel.org/stable/c/a359696856ca9409fb97655c5a8ef0f549cb6e03Patch
- https://git.kernel.org/stable/c/e4f602e3ff749ba770bf8ff10196e18358de6720Patch
- https://git.kernel.org/stable/c/e3540e5a7054d6daaf9a1415a48aacb092112a89Patch