CVE-2024-50067

uprobe: avoid out-of-bounds memory access of fetching args

References

Notes

 carnil> Introduced in dcad1a204f72 ("tracing/uprobes: Fetch args before reserving a
 carnil> ring buffer"). Vulnerable versions: 3.14-rc1.

Bugs

Status

Branch Status
upstream released (6.12-rc5) [373b9338c9722a368925d83bc622c596896b328e]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.12-upstream-stable N/A "Fixed before branching point"
6.11-upstream-stable released (6.11.6) [537ad4a431f6dddbf15d40d19f24bb9ee12b55cb]
6.6-upstream-stable released (6.6.59) [9e5f93788c9dd4309e75a56860a1ac44a8e117b9]
6.1-upstream-stable released (6.1.118) [0dc3ad9ad2188da7f090b3dbe4d2fcd9ae8ae64f]
5.10-upstream-stable needed
sid released (6.11.6-1)
6.12-trixie-security N/A "Fixed before branching point"
6.1-bookworm-security released (6.1.119-1)
5.10-bullseye-security needed