* CVE-2024-38564: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE @ 2024-06-19 13:36 Greg Kroah-Hartman 2024-06-26 6:44 ` Shung-Hsi Yu 0 siblings, 1 reply; 3+ messages in thread From: Greg Kroah-Hartman @ 2024-06-19 13:36 UTC (permalink / raw) To: linux-cve-announce; +Cc: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE bpf_prog_attach uses attach_type_to_prog_type to enforce proper attach type for BPF_PROG_TYPE_CGROUP_SKB. link_create uses bpf_prog_get and relies on bpf_prog_attach_check_attach_type to properly verify prog_type <> attach_type association. Add missing attach_type enforcement for the link_create case. Otherwise, it's currently possible to attach cgroup_skb prog types to other cgroup hooks. The Linux kernel CVE team has assigned CVE-2024-38564 to this issue. Affected and fixed versions =========================== Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.6.33 with commit 6675c541f540 Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.8.12 with commit 67929e973f5a Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.9.3 with commit b34bbc766510 Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.10-rc1 with commit 543576ec15b1 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2024-38564 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/bpf/syscall.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6675c541f540a29487a802d3135280b69b9f568d https://git.kernel.org/stable/c/67929e973f5a347f05fef064fea4ae79e7cdb5fd https://git.kernel.org/stable/c/b34bbc76651065a5eafad8ddff1eb8d1f8473172 https://git.kernel.org/stable/c/543576ec15b17c0c93301ac8297333c7b6e84ac7 ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: CVE-2024-38564: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE 2024-06-19 13:36 CVE-2024-38564: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE Greg Kroah-Hartman @ 2024-06-26 6:44 ` Shung-Hsi Yu 2024-06-27 13:29 ` Greg Kroah-Hartman 0 siblings, 1 reply; 3+ messages in thread From: Shung-Hsi Yu @ 2024-06-26 6:44 UTC (permalink / raw) To: Greg Kroah-Hartman, cve Cc: linux-kernel, bpf, Stanislav Fomichev, Eduard Zingerman, Toke Høiland-Jørgensen, Alexei Starovoitov, Andrii Nakryiko On Wed, Jun 19, 2024 at 03:36:13PM GMT, Greg Kroah-Hartman wrote: > In the Linux kernel, the following vulnerability has been resolved: > > bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE > > bpf_prog_attach uses attach_type_to_prog_type to enforce proper > attach type for BPF_PROG_TYPE_CGROUP_SKB. link_create uses > bpf_prog_get and relies on bpf_prog_attach_check_attach_type > to properly verify prog_type <> attach_type association. > > Add missing attach_type enforcement for the link_create case. > Otherwise, it's currently possible to attach cgroup_skb prog > types to other cgroup hooks. > > The Linux kernel CVE team has assigned CVE-2024-38564 to this issue. > > > Affected and fixed versions > =========================== > > Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.6.33 with commit 6675c541f540 > Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.8.12 with commit 67929e973f5a > Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.9.3 with commit b34bbc766510 > Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.10-rc1 with commit 543576ec15b1 I'd like to dispute the affected commit for this CVE. The commit that introduced the issue should instead be commit 4a1e7c0c63e02 ("bpf: Support attaching freplace programs to multiple attach points") in 5.10. When link_create() was added in commit af6eea57437a, it uses bpf_prog_get_type(attr->link_create.prog_fd, ptype) to resolve struct bpf_prog, which effectively does the requried prog->type == attach_type_to_prog_type(attach_type) check through bpf_prog_get_ok(), and thus would not allow BPF_PROG_TYPE_CGROUP_SKB to be attached to other cgroup hooks. It is in commit 4a1e7c0c63e02 ("bpf: Support attaching freplace programs to multiple attach points") that had bpf_prog_get_type() replaced with bpf_prog_get() and lead to the removal of such check, making it possible to attach BPF_PROG_TYPE_CGROUP_SKB to other cgroup hooks. [...] ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: CVE-2024-38564: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE 2024-06-26 6:44 ` Shung-Hsi Yu @ 2024-06-27 13:29 ` Greg Kroah-Hartman 0 siblings, 0 replies; 3+ messages in thread From: Greg Kroah-Hartman @ 2024-06-27 13:29 UTC (permalink / raw) To: Shung-Hsi Yu Cc: cve, linux-kernel, bpf, Stanislav Fomichev, Eduard Zingerman, Toke Høiland-Jørgensen, Alexei Starovoitov, Andrii Nakryiko On Wed, Jun 26, 2024 at 02:44:31PM +0800, Shung-Hsi Yu wrote: > On Wed, Jun 19, 2024 at 03:36:13PM GMT, Greg Kroah-Hartman wrote: > > In the Linux kernel, the following vulnerability has been resolved: > > > > bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE > > > > bpf_prog_attach uses attach_type_to_prog_type to enforce proper > > attach type for BPF_PROG_TYPE_CGROUP_SKB. link_create uses > > bpf_prog_get and relies on bpf_prog_attach_check_attach_type > > to properly verify prog_type <> attach_type association. > > > > Add missing attach_type enforcement for the link_create case. > > Otherwise, it's currently possible to attach cgroup_skb prog > > types to other cgroup hooks. > > > > The Linux kernel CVE team has assigned CVE-2024-38564 to this issue. > > > > > > Affected and fixed versions > > =========================== > > > > Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.6.33 with commit 6675c541f540 > > Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.8.12 with commit 67929e973f5a > > Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.9.3 with commit b34bbc766510 > > Issue introduced in 5.7 with commit af6eea57437a and fixed in 6.10-rc1 with commit 543576ec15b1 > > I'd like to dispute the affected commit for this CVE. > > The commit that introduced the issue should instead be commit > 4a1e7c0c63e02 ("bpf: Support attaching freplace programs to multiple > attach points") in 5.10. > > When link_create() was added in commit af6eea57437a, it uses > bpf_prog_get_type(attr->link_create.prog_fd, ptype) to resolve struct > bpf_prog, which effectively does the requried > > prog->type == attach_type_to_prog_type(attach_type) > > check through bpf_prog_get_ok(), and thus would not allow > BPF_PROG_TYPE_CGROUP_SKB to be attached to other cgroup hooks. > > It is in commit 4a1e7c0c63e02 ("bpf: Support attaching freplace programs > to multiple attach points") that had bpf_prog_get_type() replaced with > bpf_prog_get() and lead to the removal of such check, making it possible > to attach BPF_PROG_TYPE_CGROUP_SKB to other cgroup hooks. > > [...] Thanks for the information, we have now adjusted the vulnerable commit and pushed out the new json information to cve.org greg k-h ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2024-06-27 13:29 UTC | newest] Thread overview: 3+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2024-06-19 13:36 CVE-2024-38564: bpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE Greg Kroah-Hartman 2024-06-26 6:44 ` Shung-Hsi Yu 2024-06-27 13:29 ` Greg Kroah-Hartman
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.