{"id":"DEBIAN-CVE-2024-50254","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf: Free dynamically allocated bits in bpf_iter_bits_destroy()  bpf_iter_bits_destroy() uses \"kit-\u003enr_bits \u003c= 64\" to check whether the bits are dynamically allocated. However, the check is incorrect and may cause a kmemleak as shown below:  unreferenced object 0xffff88812628c8c0 (size 32):   comm \"swapper/0\", pid 1, jiffies 4294727320   hex dump (first 32 bytes): \tb0 c1 55 f5 81 88 ff ff f0 f0 f0 f0 f0 f0 f0 f0  ..U........... \tf0 f0 f0 f0 f0 f0 f0 f0 00 00 00 00 00 00 00 00  ..............   backtrace (crc 781e32cc): \t[\u003c00000000c452b4ab\u003e] kmemleak_alloc+0x4b/0x80 \t[\u003c0000000004e09f80\u003e] __kmalloc_node_noprof+0x480/0x5c0 \t[\u003c00000000597124d6\u003e] __alloc.isra.0+0x89/0xb0 \t[\u003c000000004ebfffcd\u003e] alloc_bulk+0x2af/0x720 \t[\u003c00000000d9c10145\u003e] prefill_mem_cache+0x7f/0xb0 \t[\u003c00000000ff9738ff\u003e] bpf_mem_alloc_init+0x3e2/0x610 \t[\u003c000000008b616eac\u003e] bpf_global_ma_init+0x19/0x30 \t[\u003c00000000fc473efc\u003e] do_one_initcall+0xd3/0x3c0 \t[\u003c00000000ec81498c\u003e] kernel_init_freeable+0x66a/0x940 \t[\u003c00000000b119f72f\u003e] kernel_init+0x20/0x160 \t[\u003c00000000f11ac9a7\u003e] ret_from_fork+0x3c/0x70 \t[\u003c0000000004671da4\u003e] ret_from_fork_asm+0x1a/0x30  That is because nr_bits will be set as zero in bpf_iter_bits_next() after all bits have been iterated.  Fix the issue by setting kit-\u003ebit to kit-\u003enr_bits instead of setting kit-\u003enr_bits to zero when the iteration completes in bpf_iter_bits_next(). In addition, use \"!nr_bits || bits \u003e= nr_bits\" to check whether the iteration is complete and still use \"nr_bits \u003e 64\" to indicate whether bits are dynamically allocated. The \"!nr_bits\" check is necessary because bpf_iter_bits_new() may fail before setting kit-\u003enr_bits, and this condition will stop the iteration early instead of accessing the zeroed or freed kit-\u003ebits.  Considering the initial value of kit-\u003ebits is -1 and the type of kit-\u003enr_bits is unsigned int, change the type of kit-\u003enr_bits to int. The potential overflow problem will be handled in the following patch.","modified":"2026-09-15T09:03:13.133844508Z","published":"2024-11-09T11:15:11.113Z","upstream":["CVE-2024-50254"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-50254"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50254.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.7-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-50254.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}