Answer in brief
CVE-2024-45020 records a Unknown severity vulnerability in bpf: Fix a kernel verifier crash in stacksafe(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ab470fefce2837e66b771c60858118d50bb5bb10 <7cad3174cc79519bf5f6c4441780264416822c08 || >=2793a8b015f7f1caadb9bce9c63dc659f7522676 <6e3987ac310c74bb4dd6a2fa8e46702fe505fb2b || >=2793a8b015f7f1caadb9bce9c63dc659f7522676 <bed2eb964c70b780fb55925892a74f26cb590b25 || >=6.6.15 <6.6.48 | 7cad3174cc79519bf5f6c4441780264416822c08, 6e3987ac310c74bb4dd6a2fa8e46702fe505fb2b, bed2eb964c70b780fb55925892a74f26cb590b25, 6.6.48 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Sep 11, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a kernel verifier crash in stacksafe() Daniel Hodges reported a kernel verifier crash when playing with sched-ext. Further investigation shows that the crash is due to invalid memory access in stacksafe(). More specifically, it is the following code: if (exact != NOT_EXACT && old->stack[spi].slot_type[i % BPF_REG_SIZE] != cur->stack[spi].slot_type[i % BPF_REG_SIZE]) return false; The 'i' iterates old->allocated_stack. If cur->allocated_stack < old->allocated_stack the out-of-bound access will happen. To fix the issue add 'i >= cur->allocated_stack' check such that if the condition is true, stacksafe() should fail. Otherwise, cur->stack[spi].slot_type[i % BPF_REG_SIZE] memory access is legal.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-45020 records a Unknown severity vulnerability in bpf: Fix a kernel verifier crash in stacksafe(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=ab470fefce2837e66b771c60858118d50bb5bb10 <7cad3174cc79519bf5f6c4441780264416822c08 || >=2793a8b015f7f1caadb9bce9c63dc659f7522676 <6e3987ac310c74bb4dd6a2fa8e46702fe505fb2b || >=2793a8b015f7f1caadb9bce9c63dc659f7522676 <bed2eb964c70b780fb55925892a74f26cb590b25 || >=6.6.15 <6.6.48 | 7cad3174cc79519bf5f6c4441780264416822c08, 6e3987ac310c74bb4dd6a2fa8e46702fe505fb2b, bed2eb964c70b780fb55925892a74f26cb590b25, 6.6.48 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Sep 11, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a kernel verifier crash in stacksafe() Daniel Hodges reported a kernel verifier crash when playing with sched-ext. Further investigation shows that the crash is due to invalid memory access in stacksafe(). More specifically, it is the following code: if (exact != NOT_EXACT && old->stack[spi].slot_type[i % BPF_REG_SIZE] != cur->stack[spi].slot_type[i % BPF_REG_SIZE]) return false; The 'i' iterates old->allocated_stack. If cur->allocated_stack < old->allocated_stack the out-of-bound access will happen. To fix the issue add 'i >= cur->allocated_stack' check such that if the condition is true, stacksafe() should fail. Otherwise, cur->stack[spi].slot_type[i % BPF_REG_SIZE] memory access is legal.
Quoted source text, attributed separately from HOL analysis.