Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-38566
HistoryJun 19, 2024 - 12:00 a.m.

CVE-2024-38566

2024-06-1900:00:00
ubuntu.com
ubuntu.com
3
linux kernel
cve-2024-38566
bpf
vulnerability
fix
socket->sk
verifier
assumptions
struct
socket
lsm
socket_accept
unix

AI Score

6.5

Confidence

High

In the Linux kernel, the following vulnerability has been resolved: bpf:
Fix verifier assumptions about socket->sk The verifier assumes that ‘sk’
field in ‘struct socket’ is valid and non-NULL when ‘socket’ pointer itself
is trusted and non-NULL. That may not be the case when socket was just
created and passed to LSM socket_accept hook. Fix this verifier assumption
and adjust tests.