Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Validate node_id in arena_alloc_pages() arena_alloc_pages() accepts a plain int node_id and forwards it through the entire allocation chain without any bounds checking. Validate node_id before passing it down the allocation chain in arena_alloc_pages().
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Linux / Linux317460317a02a1af512697e6e964298dedd8a163 – 31d3b4b28e55835646d6829d60023f730dd34e85
- Linux / Linux317460317a02a1af512697e6e964298dedd8a163 – e15900888c09480a4c632bc598f1c5bd39bed6d6
- Linux / Linux317460317a02a1af512697e6e964298dedd8a163 – fb66e20130f95a93ffea1677252526a9e39170b2
- Linux / Linux317460317a02a1af512697e6e964298dedd8a163 – 2845989f2ebaf7848e4eccf9a779daf3156ea0a5
- Linux / Linux6.9 – 6.9
- Linux / Linux0 – 6.9
- Linux / Linux6.12.91 – 6.12.*
- Linux / Linux6.18.33 – 6.18.*
- Linux / Linux7.0.10 – 7.0.*
- Linux / Linux7.1 – *
References
- MISChttps://git.kernel.org/stable/c/31d3b4b28e55835646d6829d60023f730dd34e85
- MISChttps://git.kernel.org/stable/c/e15900888c09480a4c632bc598f1c5bd39bed6d6
- MISChttps://git.kernel.org/stable/c/fb66e20130f95a93ffea1677252526a9e39170b2
- MISChttps://git.kernel.org/stable/c/2845989f2ebaf7848e4eccf9a779daf3156ea0a5