{"id":"DEBIAN-CVE-2024-26737","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Fix racing between bpf_timer_cancel_and_free and bpf_timer_cancel  The following race is possible between bpf_timer_cancel_and_free and bpf_timer_cancel. It will lead a UAF on the timer-\u003etimer.  bpf_timer_cancel(); \tspin_lock(); \tt = timer-\u003etime; \tspin_unlock();  \t\t\t\t\tbpf_timer_cancel_and_free(); \t\t\t\t\t\tspin_lock(); \t\t\t\t\t\tt = timer-\u003etimer; \t\t\t\t\t\ttimer-\u003etimer = NULL; \t\t\t\t\t\tspin_unlock(); \t\t\t\t\t\thrtimer_cancel(&t-\u003etimer); \t\t\t\t\t\tkfree(t);  \t/* UAF on t */ \thrtimer_cancel(&t-\u003etimer);  In bpf_timer_cancel_and_free, this patch frees the timer-\u003etimer after a rcu grace period. This requires a rcu_head addition to the \"struct bpf_hrtimer\". Another kfree(t) happens in bpf_timer_init, this does not need a kfree_rcu because it is still under the spin_lock and timer-\u003etimer has not been visible by others yet.  In bpf_timer_cancel, rcu_read_lock() is added because this helper can be used in a non rcu critical section context (e.g. from a sleepable bpf prog). Other timer-\u003etimer usages in helpers.c have been audited, bpf_timer_cancel() is the only place where timer-\u003etimer is used outside of the spin_lock.  Another solution considered is to mark a t-\u003eflag in bpf_timer_cancel and clear it after hrtimer_cancel() is done.  In bpf_timer_cancel_and_free, it busy waits for the flag to be cleared before kfree(t). This patch goes with a straight forward solution and frees timer-\u003etimer after a rcu grace period.","modified":"2026-09-15T09:03:05.183359161Z","published":"2024-04-03T17:15:51.243Z","upstream":["CVE-2024-26737"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-26737"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.82-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26737.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26737.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.7.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-26737.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}