In the Linux kernel, the following vulnerability has been resolved:
bpf: Check the remaining info_cnt before repeating btf fields
When trying to repeat the btf fields for array of nested struct, it doesn't check the remaining info_cnt. The following splat will be reported when the value of ret * nelems is greater than BTF_FIELDS_MAX:
------------[ cut here ]------------ UBSAN: array-index-out-of-bounds in ../kernel/bpf/btf.c:3951:49 index 11 is out of range for type 'btf_field_info [11]' CPU: 6 UID: 0 PID: 411 Comm: test_progs ...... 6.11.0-rc4+ #1 Tainted: [O]=OOT_MODULE Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS ... Call Trace: <TASK> dump_stack_lvl+0x57/0x70 dump_stack+0x10/0x20 ubsan_epilogue+0x9/0x40 __ubsan_handle_out_of_bounds+0x6f/0x80 ? kallsyms_lookup_name+0x48/0xb0 btf_parse_fields+0x992/0xce0 map_create+0x591/0x770 __sys_bpf+0x229/0x2410 __x64_sys_bpf+0x1f/0x30 x64_sys_call+0x199/0x9f0 do_syscall_64+0x3b/0xc0 entry_SYSCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7fea56f2cc5d ...... </TASK> ---[ end trace ]---
Fix it by checking the remaining info_cnt in btf_repeat_fields() before repeating the btf fields.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-lowlatencyUpgrade linux-image-genericUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-oem-24.04bUpgrade linux-image-lowlatency-64kUpgrade linux-image-oracleUpgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-oem-24.04Upgrade linux-image-generic-64kUpgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-6.11.0-1009-azureUpgrade linux-image-realtimeUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.11.0-1015-oemUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-awsUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-oem-24.04aUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-gcpUpgrade linux-image-raspiUpgrade linux-image-azureUpgrade linux-image-azure-fdeUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-virtual | Feb 20, 2025 | Nov 7, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub