{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-47702","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-09-30T16:00:12.945Z","datePublished":"2024-10-21T11:53:37.958Z","dateUpdated":"2026-10-03T10:55:18.539Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:55:18.539Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fail verification for sign-extension of packet data/data_end/data_meta\n\nsyzbot reported a kernel crash due to\n  commit 1f1e864b6555 (\"bpf: Handle sign-extenstin ctx member accesses\").\nThe reason is due to sign-extension of 32-bit load for\npacket data/data_end/data_meta uapi field.\n\nThe original code looks like:\n        r2 = *(s32 *)(r1 + 76) /* load __sk_buff->data */\n        r3 = *(u32 *)(r1 + 80) /* load __sk_buff->data_end */\n        r0 = r2\n        r0 += 8\n        if r3 > r0 goto +1\n        ...\nNote that __sk_buff->data load has 32-bit sign extension.\n\nAfter verification and convert_ctx_accesses(), the final asm code looks like:\n        r2 = *(u64 *)(r1 +208)\n        r2 = (s32)r2\n        r3 = *(u64 *)(r1 +80)\n        r0 = r2\n        r0 += 8\n        if r3 > r0 goto pc+1\n        ...\nNote that 'r2 = (s32)r2' may make the kernel __sk_buff->data address invalid\nwhich may cause runtime failure.\n\nCurrently, in C code, typically we have\n        void *data = (void *)(long)skb->data;\n        void *data_end = (void *)(long)skb->data_end;\n        ...\nand it will generate\n        r2 = *(u64 *)(r1 +208)\n        r3 = *(u64 *)(r1 +80)\n        r0 = r2\n        r0 += 8\n        if r3 > r0 goto pc+1\n\nIf we allow sign-extension,\n        void *data = (void *)(long)(int)skb->data;\n        void *data_end = (void *)(long)skb->data_end;\n        ...\nthe generated code looks like\n        r2 = *(u64 *)(r1 +208)\n        r2 <<= 32\n        r2 s>>= 32\n        r3 = *(u64 *)(r1 +80)\n        r0 = r2\n        r0 += 8\n        if r3 > r0 goto pc+1\nand this will cause verification failure since \"r2 <<= 32\" is not allowed\nas \"r2\" is a packet pointer.\n\nTo fix this issue for case\n  r2 = *(s32 *)(r1 + 76) /* load __sk_buff->data */\nthis patch added additional checking in is_valid_access() callback\nfunction for packet data/data_end/data_meta access. If those accesses\nare with sign-extenstion, the verification will fail.\n\n  [1] https://lore.kernel.org/bpf/000000000000c90eee061d236d37@google.com/"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerability is reached by loading a crafted eBPF program through the bpf(BPF_PROG_LOAD) syscall, which requires local access to the system; the attacker supplies the malicious LDSX instruction, not a remote peer.\nAC:L - The attacker authors the BPF bytecode directly, so the verifier bypass is accepted deterministically on every load, and the corrupted `(s32)skb->data` pointer is produced on every execution of the program with no race or unpredictable precondition; running the hook repeatedly over many skbs makes the out-of-bounds dereference a certainty.\nPR:L - Loading the affected program types requires CAP_BPF/CAP_NET_ADMIN, which BPF token delegation (`bpf_token_capable()` → `bpf_ns_capable(token->userns, cap)`, present in the affected 6.9–6.11 range) makes available to a host-unprivileged user inside a user namespace, and CAP_BPF is by design a reduced privilege whose security boundary is the verifier itself.\nUI:N - The attacker loads and attaches the program and then generates the traffic (or uses BPF_PROG_TEST_RUN) that executes it; no action from any other user is needed.\nS:U - The out-of-bounds access and resulting corruption occur within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The verifier still tracks the truncated value as a valid PTR_TO_PACKET, so the program performs kernel-mode reads at `(s32)skb->data + K` far outside any packet buffer and can copy the results into a BPF map or the packet, giving an out-of-bounds kernel memory read primitive.\nI:H - `may_access_direct_pkt_data()` grants direct packet writes to SCHED_CLS, SCHED_ACT, XDP, LWT_XMIT and SK_SKB, so the same corrupted pointer yields kernel-mode stores at an attacker-influenced address — memory corruption exploitable for further escalation.\nA:H - syzbot reported this as a kernel crash; dereferencing the mangled address from softirq/NAPI context produces a page fault or general protection fault in kernel mode, oopsing or panicking the machine."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/linux/bpf.h","kernel/bpf/verifier.c","net/core/filter.c"],"versions":[{"version":"1f1e864b65554e33fe74e3377e58b12f4302f2eb","lessThan":"4b48228eebce2ab1b01e3133da822164472b7e46","status":"affected","versionType":"git"},{"version":"1f1e864b65554e33fe74e3377e58b12f4302f2eb","lessThan":"f1620c93a1ec950d87ef327a565d3907736d3340","status":"affected","versionType":"git"},{"version":"1f1e864b65554e33fe74e3377e58b12f4302f2eb","lessThan":"f09757fe97a225ae505886eac572e4cbfba96537","status":"affected","versionType":"git"},{"version":"1f1e864b65554e33fe74e3377e58b12f4302f2eb","lessThan":"92de36080c93296ef9005690705cba260b9bd68a","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/linux/bpf.h","kernel/bpf/verifier.c","net/core/filter.c"],"versions":[{"version":"6.6","status":"affected"},{"version":"0","lessThan":"6.6","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.10.13","lessThanOrEqual":"6.10.*","status":"unaffected","versionType":"semver"},{"version":"6.11.2","lessThanOrEqual":"6.11.*","status":"unaffected","versionType":"semver"},{"version":"6.12","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.10.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.11.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6","versionEndExcluding":"6.12"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4b48228eebce2ab1b01e3133da822164472b7e46"},{"url":"https://git.kernel.org/stable/c/f1620c93a1ec950d87ef327a565d3907736d3340"},{"url":"https://git.kernel.org/stable/c/f09757fe97a225ae505886eac572e4cbfba96537"},{"url":"https://git.kernel.org/stable/c/92de36080c93296ef9005690705cba260b9bd68a"}],"title":"bpf: Fail verification for sign-extension of packet data/data_end/data_meta","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-47702","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-10-21T13:04:24.861686Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-10-21T13:14:13.443Z"}}]}}