CVE-2024-56615·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: bpf: fix OOB devmap writes when deleting elements Jordy reported issue against XSKMAP which also applies to DEVMAP - the index used for accessing map entry, due to being a signed integer, causes the OOB writes. Fix is simple as changing the type from int to u32, however, when compared to XSKMAP case, one more thing needs to be addressed. When map is released from system via dev_map_free(), we iterate through all of the entries and an iterator variable is also an int, which implies OOB accesses. Again, change it to be u32. Example splat below: [ 160.724676] BUG: unable to handle page fault for address: ffffc8fc2c001000 [ 160.731662] #PF: supervisor read access in kernel mode [ 160.736876] #PF: error_code(0x0000) - not-present page [ 160.742095] PGD 0 P4D 0 [ 160.744678] Oops: Oops: 0000 [#1] PREEMPT SMP [ 160.749106] CPU: 1 UID: 0 PID: 520 Comm: kworker/u145:12 Not tainted 6.12.0-rc1+ #487 [ 160.757050] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019 [ 160.767642] Workqueue: events_unbound bpf_map_free_deferred [ 160.773308] RIP: 0010:dev_map_free+0x77/0x170 [ 160.777735] Code: 00 e8 fd 91 ed ff e8 b8 73 ed ff 41 83 7d 18 19 74 6e 41 8b 45 24 49 8b bd f8 00 00 00 31 db 85 c0 74 48 48 63 c3 48 8d 04 c7 <48> 8b 28 48 85 ed 74 30 48 8b 7d 18 48 85 ff 74 05 e8 b3 52 fa ff [ 160.796777] RSP: 0018:ffffc9000ee1fe38 EFLAGS: 00010202 [ 160.802086] RAX: ffffc8fc2c001000 RBX: 0000000080000000 RCX: 0000000000000024 [ 160.809331] RDX: 0000000000000000 RSI: 0000000000000024 RDI: ffffc9002c001000 [ 160.816576] RBP: 0000000000000000 R08: 0000000000000023 R09: 0000000000000001 [ 160.823823] R10: 0000000000000001 R11: 00000000000ee6b2 R12: dead000000000122 [ 160.831066] R13: ffff88810c928e00 R14: ffff8881002df405 R15: 0000000000000000 [ 160.838310] FS: 0000000000000000(0000) GS:ffff8897e0c40000(0000) knlGS:0000000000000000 [ 160.846528] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 160.852357] CR2: ffffc8fc2c001000 CR3: 0000000005c32006 CR4: 00000000007726f0 [ 160.859604] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 160.866847] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 160.874092] PKRU: 55555554 [ 160.876847] Call Trace: [ 160.879338] <TASK> [ 160.881477] ? __die+0x20/0x60 [ 160.884586] ? page_fault_oops+0x15a/0x450 [ 160.888746] ? search_extable+0x22/0x30 [ 160.892647] ? search_bpf_extables+0x5f/0x80 [ 160.896988] ? exc_page_fault+0xa9/0x140 [ 160.900973] ? asm_exc_page_fault+0x22/0x30 [ 160.905232] ? dev_map_free+0x77/0x170 [ 160.909043] ? dev_map_free+0x58/0x170 [ 160.912857] bpf_map_free_deferred+0x51/0x90 [ 160.917196] process_one_work+0x142/0x370 [ 160.921272] worker_thread+0x29e/0x3b0 [ 160.925082] ? rescuer_thread+0x4b0/0x4b0 [ 160.929157] kthread+0xd4/0x110 [ 160.932355] ? kthread_park+0x80/0x80 [ 160.936079] ret_from_fork+0x2d/0x50 [ 160.943396] ? kthread_park+0x80/0x80 [ 160.950803] ret_from_fork_asm+0x11/0x20 [ 160.958482] </TASK>
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.12.5
- Published
- 2024-12-27
Affected versions
From: 6.7
Until: 6.12.5
Fixed in: 6.12.5
How to fix this CVE
Update your Linux kernel to version 6.12.5 or later to fix an out-of-bounds memory access vulnerability in the eBPF DEVMAP subsystem. This vulnerability allows privileged local attackers to read and write kernel memory, potentially leading to denial of service or privilege escalation. Apply the kernel update immediately through your distribution's package manager.
sudo dnf update kernel kernel-headers kernel-develDefensia detects this vulnerability
How to check if you are affected
- Check your kernel version: uname -r — verify it is 6.12.5 or later
- Confirm DEVMAP is in use by checking: grep -r 'bpf_map_type_devmap' /sys/kernel/debug/tracing/ 2>/dev/null || echo 'No active DEVMAP found'
- Look for page fault oops errors in kernel logs: sudo journalctl -k | grep -i 'page fault\|oops\|devmap'
- Verify the patch was applied: grep -i 'devmap.*oob\|fix.*signed.*int' /proc/version || uname -r | grep -E '6\.12\.[5-9]|6\.[13-9]'
FAQ
What is CVE-2024-56615?
CVE-2024-56615 is a high-severity out-of-bounds memory access flaw in the Linux kernel's eBPF DEVMAP implementation. A privileged local attacker can trigger integer signedness errors when deleting map elements, allowing arbitrary kernel memory read/write operations.
Is CVE-2024-56615 being actively exploited?
No, CVE-2024-56615 is not listed in the CISA Known Exploited Vulnerabilities catalog and no public exploits are available. However, the vulnerability requires local access with elevated privileges, limiting real-world exposure.
What versions of Kernel are affected by CVE-2024-56615?
Kernel versions 6.7 through 6.12.4 are vulnerable. Version 6.12.5 and later contain the fix.
How do I check if my server is vulnerable to CVE-2024-56615?
Run 'uname -r' to check your kernel version. If it reports any version from 6.7.x to 6.12.4, your system is vulnerable and requires immediate patching.
Does Defensia detect CVE-2024-56615?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Kernel is installed on a monitored server, CVE-2024-56615 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/0f170e91d3063ca60baec4bd9f544faf3bfe29eb
- https://git.kernel.org/stable/c/178e31df1fb3d9e0890eb471da16709cbc82edee
- https://git.kernel.org/stable/c/70f3de869865f9c3da0508a5ea29f6f4c1889057
- https://git.kernel.org/stable/c/8e858930695d3ebec423e85384c95427258c294f
- https://git.kernel.org/stable/c/98c03d05936d846073df8f550e9e8bf0dde1d77f
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-56615. Free for 1 server.
Get started free