{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2024-26883","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-19T14:20:24.185Z","datePublished":"2024-04-17T10:27:39.036Z","dateUpdated":"2026-08-05T11:28:08.431Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:28:08.431Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix stackmap overflow check on 32-bit arches\n\nThe stackmap code relies on roundup_pow_of_two() to compute the number\nof hash buckets, and contains an overflow check by checking if the\nresulting value is 0. However, on 32-bit arches, the roundup code itself\ncan overflow by doing a 32-bit left-shift of an unsigned long value,\nwhich is undefined behaviour, so it is not guaranteed to truncate\nneatly. This was triggered by syzbot on the DEVMAP_HASH type, which\ncontains the same check, copied from the hashtab code.\n\nThe commit in the fixes tag actually attempted to fix this, but the fix\ndid not account for the UB, so the fix only works on CPUs where an\noverflow does result in a neat truncation to zero, which is not\nguaranteed. Checking the value before rounding does not have this\nproblem."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerability is reached solely through the bpf(BPF_MAP_CREATE) syscall from a local process; no network or remote peer data is involved in stackmap creation.\nAC:L - A single syscall with max_entries > 0x80000000 deterministically bypasses the overflow check on a 32-bit kernel — no race, no memory-layout precondition, and the attacker fully controls max_entries and value_size (hence the OOB write stride).\nPR:L - Creating a BPF_MAP_TYPE_STACK_TRACE map requires CAP_BPF (bpf_capable()/bpf_token_capable()), a delegated capability routinely granted to unprivileged observability agents, container runtimes and BPF-token-holding workloads rather than full root.\nUI:N - The attacker triggers the entire flaw with its own syscall; no victim action, mount, or file open is needed.\nS:U - The corruption is confined to kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The truncated allocation leaves pcpu_freelist nodes pointing into arbitrary kernel memory, which subsequent bpf_get_stackid()/map lookups copy back to userspace, and the resulting heap corruption is generally leverageable for arbitrary kernel memory disclosure.\nI:H - pcpu_freelist_populate() performs ~2^31 pointer writes at an attacker-chosen stride past a tiny (attacker-sized) allocation, an unbounded out-of-bounds write of kernel pointer values that is exploitable for control-flow hijacking.\nA:H - The wild writes sweep gigabytes of kernel address space and reliably corrupt slab metadata and unmapped pages, guaranteeing an oops/panic; even on trees where the write is avoided the path is a hard map-creation failure."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/stackmap.c"],"versions":[{"version":"063c722dd9d285d877e6fd499e753d6224f4c046","lessThan":"d0e214acc59145ce25113f617311aa79dda39cb3","status":"affected","versionType":"git"},{"version":"7e3a6b820535eb395784060ae26c5af579528fa0","lessThan":"21e5fa4688e1a4d3db6b72216231b24232f75c1d","status":"affected","versionType":"git"},{"version":"8032bf2af9ce26b3a362b9711d15f626ab946a74","lessThan":"15641007df0f0d35fa28742b25c2a7db9dcd6895","status":"affected","versionType":"git"},{"version":"6183f4d3a0a2ad230511987c6c362ca43ec0055f","lessThan":"ca1f06e72dec41ae4f76e7b1a8a97265447b46ae","status":"affected","versionType":"git"},{"version":"6183f4d3a0a2ad230511987c6c362ca43ec0055f","lessThan":"f06899582ccee09bd85d0696290e3eaca9aa042d","status":"affected","versionType":"git"},{"version":"6183f4d3a0a2ad230511987c6c362ca43ec0055f","lessThan":"7070b274c7866a4c5036f8d54fcaf315c64ac33a","status":"affected","versionType":"git"},{"version":"6183f4d3a0a2ad230511987c6c362ca43ec0055f","lessThan":"43f798b9036491fb014b55dd61c4c5c3193267d0","status":"affected","versionType":"git"},{"version":"6183f4d3a0a2ad230511987c6c362ca43ec0055f","lessThan":"0971126c8164abe2004b8536b49690a0d6005b0a","status":"affected","versionType":"git"},{"version":"6183f4d3a0a2ad230511987c6c362ca43ec0055f","lessThan":"7a4b21250bf79eef26543d35bd390448646c536b","status":"affected","versionType":"git"},{"version":"253150830a012adfccf90afcebae8fda5b05a80f","status":"affected","versionType":"git"},{"version":"766107351731ae223ebf60ca22bdfeb47ce6acc8","status":"affected","versionType":"git"},{"version":"4.19.177","lessThan":"4.19.311","status":"affected","versionType":"semver"},{"version":"5.4.99","lessThan":"5.4.273","status":"affected","versionType":"semver"},{"version":"5.10.17","lessThan":"5.10.214","status":"affected","versionType":"semver"},{"version":"4.9.258","lessThan":"4.10","status":"affected","versionType":"semver"},{"version":"4.14.222","lessThan":"4.15","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["kernel/bpf/stackmap.c"],"versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","status":"unaffected","versionType":"semver"},{"version":"4.19.311","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.273","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.214","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.153","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.83","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.23","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.11","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8.2","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.177","versionEndExcluding":"4.19.311"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.99","versionEndExcluding":"5.4.273"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.17","versionEndExcluding":"5.10.214"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"5.15.153"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.1.83"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.6.23"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.7.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.8.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.9.258"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14.222"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/d0e214acc59145ce25113f617311aa79dda39cb3"},{"url":"https://git.kernel.org/stable/c/21e5fa4688e1a4d3db6b72216231b24232f75c1d"},{"url":"https://git.kernel.org/stable/c/15641007df0f0d35fa28742b25c2a7db9dcd6895"},{"url":"https://git.kernel.org/stable/c/ca1f06e72dec41ae4f76e7b1a8a97265447b46ae"},{"url":"https://git.kernel.org/stable/c/f06899582ccee09bd85d0696290e3eaca9aa042d"},{"url":"https://git.kernel.org/stable/c/7070b274c7866a4c5036f8d54fcaf315c64ac33a"},{"url":"https://git.kernel.org/stable/c/43f798b9036491fb014b55dd61c4c5c3193267d0"},{"url":"https://git.kernel.org/stable/c/0971126c8164abe2004b8536b49690a0d6005b0a"},{"url":"https://git.kernel.org/stable/c/7a4b21250bf79eef26543d35bd390448646c536b"}],"title":"bpf: Fix stackmap overflow check on 32-bit arches","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:21:05.381Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/d0e214acc59145ce25113f617311aa79dda39cb3","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/21e5fa4688e1a4d3db6b72216231b24232f75c1d","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/15641007df0f0d35fa28742b25c2a7db9dcd6895","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/ca1f06e72dec41ae4f76e7b1a8a97265447b46ae","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/f06899582ccee09bd85d0696290e3eaca9aa042d","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/7070b274c7866a4c5036f8d54fcaf315c64ac33a","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/43f798b9036491fb014b55dd61c4c5c3193267d0","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/0971126c8164abe2004b8536b49690a0d6005b0a","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/7a4b21250bf79eef26543d35bd390448646c536b","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-26883","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-09-10T15:48:22.381696Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-11T17:33:25.228Z"}},{"x_adpType":"supplier","providerMetadata":{"orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP","dateUpdated":"2026-05-12T11:50:06.933Z"},"affected":[{"vendor":"Siemens","product":"SIMATIC S7-1500 TM MFP - GNU/Linux subsystem","versions":[{"status":"affected","version":"0","lessThan":"*","versionType":"custom"}],"defaultStatus":"unknown"}],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-265688.html"}]}]},"dataVersion":"5.2"}