#VU108686 Resource management error in Linux kernel - CVE-2024-58098
Published: May 6, 2025 / Updated: May 10, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the check_func_call(), mark_subprog_changes_pkt_data(), visit_func_call_insn() and visit_insn() functions in kernel/bpf/verifier.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/1d572c60488b52882b719ed273767ee3b280413d
- https://git.kernel.org/stable/c/51081a3f25c742da5a659d7fc6fd77ebfdd555be
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.25
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.90