CVE-2024-41003 is a vulnerability in the Linux kernel's BPF verifier, specifically affecting the reg_set_min_max function. It involves a register invariant violation that occurs when the verifier incorrectly handles "fake" registers during branch analysis, leading to a corruption of the fake_reg state. This flaw impacts the Linux kernel. The vulnerability is rated as HIGH severity with a CVSS score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating that a local attacker with low privileges can exploit it without user interaction. Successful exploitation could lead to high impacts on confidentiality, integrity, and availability, likely due to potential privilege escalation or denial of service. The underlying issue is categorized as CWE-787 (Out-of-bounds Write). Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and there is minimal community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.8, < 6.9.7CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.10:rc1:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.10:rc2:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.10:rc3:*:*:*:*:*:* | ||
6.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.10:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.