CVE-2023-52462

    Dashboard / Vulnerabilities / CVE-2023-52462

    CVE-2023-52462

    Published: 23 Feb 2024Last Modified: 12 Aug 2026

    Summary: bpf: fix check for attempt to corrupt spilled pointer

    Details: In the Linux kernel, the following vulnerability has been resolved: bpf: fix check for attempt to corrupt spilled pointer When register is spilled onto a stack as a 1/2/4-byte register, we set slot_type[BPF_REG_SIZE - 1] (plus potentially few more below it, depending on actual spill size). So to check if some stack slot has spilled register we need to consult slot_type[7], not slot_type[0]. To avoid the need to remember and double-check this in the future, just use is_spilled_reg() helper.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- cdd73a5ed0840da88a3b9ad353f568e6f156d417

    Affected versions

    v5.10.208
    v5.10.207
    v5.10.206
    v5.10.205
    v5.10.204
    v5.10.203
    v5.10.202
    v5.10.201
    v5.10.200
    v5.10.199
    v5.10.198
    v5.10.197
    v5.10.196
    v5.10.195
    v5.10.194
    v5.10.193
    v5.10.192
    v5.10.191
    v5.10.190
    v5.10.189
    v5.10.188
    v5.10.187
    v5.10.186
    v5.10.185
    v5.10.184
    v5.10.183
    v5.10.182
    v5.10.181
    v5.10.180
    v5.10.179
    v5.10.178
    v5.10.177
    v5.10.176
    v5.10.175
    v5.10.174
    v5.10.173
    v5.10.172
    v5.10.171
    v5.10.170
    v5.10.169
    v5.10.168
    v5.10.167
    v5.10.166
    v5.10.165
    v5.10.164
    v5.10.163

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-52462 | CVE-DB