Answer in brief
CVE-2024-43840 records a Unknown severity vulnerability in bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=efc9909fdce00a827a37609628223cd45bf95d0b <077149478497b2f00ff4fd9da2c892defa6418d8 || >=efc9909fdce00a827a37609628223cd45bf95d0b <d9664e6ff040798a46cdc5d401064f55b8676c83 || >=efc9909fdce00a827a37609628223cd45bf95d0b <6d218fcc707d6b2c3616b6cd24b948fd4825cfec || >=efc9909fdce00a827a37609628223cd45bf95d0b <19d3c179a37730caf600a97fed3794feac2b197b | 077149478497b2f00ff4fd9da2c892defa6418d8, d9664e6ff040798a46cdc5d401064f55b8676c83, 6d218fcc707d6b2c3616b6cd24b948fd4825cfec, 19d3c179a37730caf600a97fed3794feac2b197b |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Aug 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG When BPF_TRAMP_F_CALL_ORIG is set, the trampoline calls __bpf_tramp_enter() and __bpf_tramp_exit() functions, passing them the struct bpf_tramp_image *im pointer as an argument in R0. The trampoline generation code uses emit_addr_mov_i64() to emit instructions for moving the bpf_tramp_image address into R0, but emit_addr_mov_i64() assumes the address to be in the vmalloc() space and uses only 48 bits. Because bpf_tramp_image is allocated using kzalloc(), its address can use more than 48-bits, in this case the trampoline will pass an invalid address to __bpf_tramp_enter/exit() causing a kernel crash. Fix this by using emit_a64_mov_i64() in place of emit_addr_mov_i64() as it can work with addresses that are greater than 48-bits.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-43840 records a Unknown severity vulnerability in bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=efc9909fdce00a827a37609628223cd45bf95d0b <077149478497b2f00ff4fd9da2c892defa6418d8 || >=efc9909fdce00a827a37609628223cd45bf95d0b <d9664e6ff040798a46cdc5d401064f55b8676c83 || >=efc9909fdce00a827a37609628223cd45bf95d0b <6d218fcc707d6b2c3616b6cd24b948fd4825cfec || >=efc9909fdce00a827a37609628223cd45bf95d0b <19d3c179a37730caf600a97fed3794feac2b197b | 077149478497b2f00ff4fd9da2c892defa6418d8, d9664e6ff040798a46cdc5d401064f55b8676c83, 6d218fcc707d6b2c3616b6cd24b948fd4825cfec, 19d3c179a37730caf600a97fed3794feac2b197b |
| Linux/Linuxgeneric | 6.0 | Not reported |
Published upstream
Aug 17, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix trampoline for BPF_TRAMP_F_CALL_ORIG When BPF_TRAMP_F_CALL_ORIG is set, the trampoline calls __bpf_tramp_enter() and __bpf_tramp_exit() functions, passing them the struct bpf_tramp_image *im pointer as an argument in R0. The trampoline generation code uses emit_addr_mov_i64() to emit instructions for moving the bpf_tramp_image address into R0, but emit_addr_mov_i64() assumes the address to be in the vmalloc() space and uses only 48 bits. Because bpf_tramp_image is allocated using kzalloc(), its address can use more than 48-bits, in this case the trampoline will pass an invalid address to __bpf_tramp_enter/exit() causing a kernel crash. Fix this by using emit_a64_mov_i64() in place of emit_addr_mov_i64() as it can work with addresses that are greater than 48-bits.
Quoted source text, attributed separately from HOL analysis.