{"id":"DEBIAN-CVE-2024-50161","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Check the remaining info_cnt before repeating btf fields  When trying to repeat the btf fields for array of nested struct, it doesn't check the remaining info_cnt. The following splat will be reported when the value of ret * nelems is greater than BTF_FIELDS_MAX:    ------------[ cut here ]------------   UBSAN: array-index-out-of-bounds in ../kernel/bpf/btf.c:3951:49   index 11 is out of range for type 'btf_field_info [11]'   CPU: 6 UID: 0 PID: 411 Comm: test_progs ...... 6.11.0-rc4+ #1   Tainted: [O]=OOT_MODULE   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS ...   Call Trace:    \u003cTASK\u003e    dump_stack_lvl+0x57/0x70    dump_stack+0x10/0x20    ubsan_epilogue+0x9/0x40    __ubsan_handle_out_of_bounds+0x6f/0x80    ? kallsyms_lookup_name+0x48/0xb0    btf_parse_fields+0x992/0xce0    map_create+0x591/0x770    __sys_bpf+0x229/0x2410    __x64_sys_bpf+0x1f/0x30    x64_sys_call+0x199/0x9f0    do_syscall_64+0x3b/0xc0    entry_SYSCALL_64_after_hwframe+0x4b/0x53   RIP: 0033:0x7fea56f2cc5d   ......    \u003c/TASK\u003e   ---[ end trace ]---  Fix it by checking the remaining info_cnt in btf_repeat_fields() before repeating the btf fields.","modified":"2026-09-15T09:02:59.001500097Z","published":"2024-11-07T10:15:07.480Z","upstream":["CVE-2024-50161"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-50161"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50161.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50161.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}