CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-42072

Critical Severity
Linux
SVRS
70/100

CVSSv3
7.8/10

EPSS
0.00034/1

CVE-2024-42072 is a vulnerability in the Linux kernel's Berkeley Packet Filter (BPF) component related to handling negative offsets in 'may_goto' instructions. This BPF vulnerability can lead to incorrect patching and potential infinite loop scenarios within the kernel verifier. Although CVSS scores it at 7.8, SOCRadar's Vulnerability Risk Score (SVRS) is 70, indicating a moderate risk. The improper handling of negative offsets in 'may_goto' could be exploited, although mitigation complexities are expected. The flaw stems from issues in how the kernel patches and verifies BPF programs using 'may_goto' with negative offsets, creating opportunities for unexpected behavior. Addressing CVE-2024-42072 is crucial to maintain the stability and security of systems relying on the Linux kernel, especially given the widespread use of BPF in networking and tracing. The vulnerability highlights the importance of rigorous verification processes in kernel components.

No tags available
CVSS:3.1
AV:L
AC:L
PR:L
UI:N
S:U
C:H
I:H
A:H
2024-07-29

2024-07-30

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-42072 | Linux Kernel up to 6.9.7 bpf may_goto infinite loop (175827e04f4b/2b2efe1937ca / Nessus ID 215820)
vuldb.com2025-02-12
CVE-2024-42072 | Linux Kernel up to 6.9.7 bpf may_goto infinite loop (175827e04f4b/2b2efe1937ca / Nessus ID 215820) | A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.9.7. This affects the function may_goto of the component bpf. The manipulation leads to infinite loop. This vulnerability is uniquely identified as CVE-2024-42072
vuldb.com
rss
forum
news

Social Media

CVE-2024-42072 (CVSS:7.8, HIGH) is Analyzed. In the Linux kernel, the following vulnerability has been resolved: bpf: Fix may_goto with negative offset. Zac's syzb..https://t.co/QgauR8D32d #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
0
0
0
CVE-2024-42072 In the Linux kernel, the following vulnerability has been resolved: bpf: Fix may_goto with negative offset. Zac's syzbot crafted a bpf prog that exposed two bugs in… https://t.co/2BAHNRUYEv
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
OSLinuxlinux_kernel

References

ReferenceLink
416BAAA9-DC9F-4396-8D5F-8C081FB06D67https://git.kernel.org/stable/c/175827e04f4be53f3dfb57edf12d0d49b18fd939
416BAAA9-DC9F-4396-8D5F-8C081FB06D67https://git.kernel.org/stable/c/2b2efe1937ca9f8815884bd4dcd5b32733025103

CWE Details

No CWE details found for this CVE

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence