CVE-2023-52452

Public on 2024-02-22
Modified on 2024-02-28
Description
bpf: Fix accesses to uninit stack slots

Privileged programs are supposed to be able to read uninitialized stack
memory (ever since 6715df8d5) but, before this patch, these accesses
were permitted inconsistently. In particular, accesses were permitted
above state->allocated_stack, but not below it. In other words, if the
stack was already "large enough", the access was permitted, but
otherwise the access was rejected instead of being allowed to "grow the
stack".
Severity
Medium severity
Medium
CVSS v3 Base Score
4.7
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 kernel No Fix Planned
HAQM Linux 2 - Core kernel Pending Fix
HAQM Linux 2 - Kernel-5.10 Extra kernel Pending Fix
HAQM Linux 2 - Kernel-5.15 Extra kernel Pending Fix
HAQM Linux 2 - Kernel-5.4 Extra kernel Pending Fix
HAQM Linux 2023 kernel Pending Fix

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H