Review reviewHigh

CVE-2024-26883

Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, debian linux

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stackmap overflow check on 32-bit arches The stackmap code relies on roundup_pow_of_two() to compute the number of hash buckets, and contains an overflow check by checking if the resulting value is 0. However, on 32-bit arches, the roundup code itself can overflow by doing a 32-bit left-shift of an unsigned long value, which is undefined behaviour, so it is not guaranteed to truncate neatly. This was triggered by syzbot on the DEVMAP_HASH type, which contains the same check, copied from the hashtab code. The commit...

CVSS
7.8
EPSS
0.25%
16.4% percentile
CISA KEV
Not listed
Published
2024.04.17
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.25%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stackmap overflow check on 32-bit arches The stackmap code relies on roundup_pow_of_two() to compute the number of hash buckets, and contains an overflow check by checking if the resulting value is 0. However, on 32-bit arches, the roundup code itself can overflow by doing a 32-bit left-shift of an unsigned long value, which is undefined behaviour, so it is not guaranteed to truncate neatly. This was triggered by syzbot on the DEVMAP_HASH type, which contains the same check, copied from the hashtab code. The commit...

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, debian linux
Affected versions
>= 063c722dd9d285d877e6fd499e753d6224f4c046 < d0e214acc59145ce25113f617311aa79dda39cb3, >= 7e3a6b820535eb395784060ae26c5af579528fa0 < 21e5fa4688e1a4d3db6b72216231b24232f75c1d, >= 8032bf2af9ce26b3a362b9711d15f626ab946a74 < 15641007df0f0d35fa28742b25c2a7db9dcd6895, >= 6183f4d3a0a2ad230511987c6c362ca43ec0055f < ca1f06e72dec41ae4f76e7b1a8a97265447b46ae, >= 6183f4d3a0a2ad230511987c6c362ca43ec0055f < f06899582ccee09bd85d0696290e3eaca9aa042d, >= 6183f4d3a0a2ad230511987c6c362ca43ec0055f < 7070b274c7866a4c5036f8d54fcaf315c64ac33a, >= 6183f4d3a0a2ad230511987c6c362ca43ec0055f < 43f798b9036491fb014b55dd61c4c5c3193267d0, >= 6183f4d3a0a2ad230511987c6c362ca43ec0055f < 0971126c8164abe2004b8536b49690a0d6005b0a, >= 6183f4d3a0a2ad230511987c6c362ca43ec0055f < 7a4b21250bf79eef26543d35bd390448646c536b, >= 253150830a012adfccf90afcebae8fda5b05a80f, >= 766107351731ae223ebf60ca22bdfeb47ce6acc8, >= 4.19.177 < 4.19.311, >= 5.4.99 < 5.4.273, >= 5.10.17 < 5.10.214, >= 4.9.258 < 4.10, >= 4.14.222 < 4.15, >= 5.11, 10.0, >= 5.11 < 5.15.153, >= 5.16 < 6.1.83
Fixed versions
4.10, 4.15, 4.19.311, 5.4.273, 5.10.214, 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-119
CVE-2024-26883 — Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, debian linux | SECUFOCUS NOW