CVE-2024-47728

bpf: Zero former ARG_PTR_TO_{LONG,INT} args in case of error

References

Notes

 carnil> Introduced in 8a67f2de9b1d ("bpf: expose bpf_strtol and bpf_strtoul to all
 carnil> program types")
 carnil> d7a4cb9b6705 ("bpf: Introduce bpf_strtol and bpf_strtoul helpers"). Vulnerable
 carnil> versions: 5.2-rc1.

Bugs

Status

Branch Status
upstream released (6.12-rc1) [4b3786a6c5397dc220b1483d8e2f4867743e966f]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.11-upstream-stable released (6.11.2) [594a9f5a8d2de2573a856e506f77ba7dd2cefc6a]
6.10-upstream-stable released (6.10.13) [599d15b6d03356a97bff7a76155c5604c42a2962]
6.6-upstream-stable released (6.6.54) [a634fa8e480ac2423f86311a602f6295df2c8ed0]
6.1-upstream-stable released (6.1.113) [8397bf78988f3ae9dbebb0200189a62a57264980]
5.10-upstream-stable needed
4.19-upstream-stable N/A "Vulnerable code not present"
sid released (6.11.2-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.115-1)
5.10-bullseye-security needed