{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-53125",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-11-19T17:17:24.995Z",
        "datePublished": "2024-12-04T14:11:09.326Z",
        "dateUpdated": "2026-08-05T11:43:55.135Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:43:55.135Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: sync_linked_regs() must preserve subreg_def\n\nRange propagation must not affect subreg_def marks, otherwise the\nfollowing example is rewritten by verifier incorrectly when\nBPF_F_TEST_RND_HI32 flag is set:\n\n  0: call bpf_ktime_get_ns                   call bpf_ktime_get_ns\n  1: r0 &= 0x7fffffff       after verifier   r0 &= 0x7fffffff\n  2: w1 = w0                rewrites         w1 = w0\n  3: if w0 < 10 goto +0     -------------->  r11 = 0x2f5674a6     (r)\n  4: r1 >>= 32                               r11 <<= 32           (r)\n  5: r0 = r1                                 r1 |= r11            (r)\n  6: exit;                                   if w0 < 0xa goto pc+0\n                                             r1 >>= 32\n                                             r0 = r1\n                                             exit\n\n(or zero extension of w1 at (2) is missing for architectures that\n require zero extension for upper register half).\n\nThe following happens w/o this patch:\n- r0 is marked as not a subreg at (0);\n- w1 is marked as subreg at (2);\n- w1 subreg_def is overridden at (3) by copy_register_state();\n- w1 is read at (5) but mark_insn_zext() does not mark (2)\n  for zero extension, because w1 subreg_def is not set;\n- because of BPF_F_TEST_RND_HI32 flag verifier inserts random\n  value for hi32 bits of (2) (marked (r));\n- this random value is read at (5)."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The flaw is in the BPF verifier and is reached only by loading a crafted eBPF program through the local `bpf(BPF_PROG_LOAD)` syscall. There is no remote or adjacent path to `check_cond_jmp_op()`/`sync_linked_regs()`.\nAC:L - The attacker authors the entire BPF instruction sequence, so the register-linking, conditional jump, and the stale upper-32-bit value are fully deterministic and under their control. On the affected architectures (ppc64, s390x, riscv, sparc64, mips, arm32, parisc, x86-32 — all major deployment targets from cloud mainframes to embedded/automotive) the missing zero-extension is emitted reliably on every run.\nPR:L - An unprivileged local user can load BPF_PROG_TYPE_SOCKET_FILTER/CGROUP_SKB programs whenever `kernel.unprivileged_bpf_disabled=0`, and container users can load programs via delegated BPF tokens; otherwise only CAP_BPF, not real root, is needed. No administrative privilege in the init namespace is required.\nUI:N - The attacker loads and runs their own BPF program end-to-end; no action by any other user or administrator is involved.\nS:U - The corruption stays within the kernel's own security authority — it is a standard local privilege-escalation primitive with no VM, IOMMU, or sandbox boundary crossed.\nC:H - The verifier believes the register is zero-extended and range-bounded while at runtime its upper 32 bits hold an attacker-supplied value, so bounds checks on map-value/stack accesses are bypassed with an attacker-chosen 64-bit displacement, yielding arbitrary kernel memory disclosure.\nI:H - The same verifier/runtime divergence permits out-of-bounds *writes* at an attacker-controlled offset, providing an arbitrary kernel write primitive suitable for control-flow hijacking and privilege escalation.\nA:H - Out-of-bounds accesses at an unbounded attacker-controlled offset trivially fault on unmapped or protected kernel memory, causing an oops or panic; the incorrectly JITed program also executes with garbage register state."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "kernel/bpf/verifier.c"
                    ],
                    "versions": [
                        {
                            "version": "75748837b7e56919679e02163f45d5818c644d03",
                            "lessThan": "dadf82c1b2608727bcc306843b540cd7414055a7",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "75748837b7e56919679e02163f45d5818c644d03",
                            "lessThan": "b57ac2d92c1f565743f6890a5b9cf317ed856b09",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "75748837b7e56919679e02163f45d5818c644d03",
                            "lessThan": "60fd3538d2a8fd44c41d25088c0ece3e1fd30659",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "75748837b7e56919679e02163f45d5818c644d03",
                            "lessThan": "bfe9446ea1d95f6cb7848da19dfd58d2eec6fd84",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "75748837b7e56919679e02163f45d5818c644d03",
                            "lessThan": "e2ef0f317a52e678fe8fa84b94d6a15b466d6ff0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "75748837b7e56919679e02163f45d5818c644d03",
                            "lessThan": "e9bd9c498cb0f5843996dbe5cbce7a1836a83c70",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "kernel/bpf/verifier.c"
                    ],
                    "versions": [
                        {
                            "version": "5.10",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.10",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.232",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.175",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.121",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.67",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.11.6",
                            "lessThanOrEqual": "6.11.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10",
                                    "versionEndExcluding": "5.10.232"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10",
                                    "versionEndExcluding": "5.15.175"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10",
                                    "versionEndExcluding": "6.1.121"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10",
                                    "versionEndExcluding": "6.6.67"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10",
                                    "versionEndExcluding": "6.11.6"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10",
                                    "versionEndExcluding": "6.12"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/dadf82c1b2608727bcc306843b540cd7414055a7"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b57ac2d92c1f565743f6890a5b9cf317ed856b09"
                },
                {
                    "url": "https://git.kernel.org/stable/c/60fd3538d2a8fd44c41d25088c0ece3e1fd30659"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bfe9446ea1d95f6cb7848da19dfd58d2eec6fd84"
                },
                {
                    "url": "https://git.kernel.org/stable/c/e2ef0f317a52e678fe8fa84b94d6a15b466d6ff0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/e9bd9c498cb0f5843996dbe5cbce7a1836a83c70"
                }
            ],
            "title": "bpf: sync_linked_regs() must preserve subreg_def",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
                    },
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T20:46:07.020Z"
                }
            }
        ]
    }
}