Answer in brief
CVE-2024-58237 records a Unknown severity vulnerability in bpf: consider that tail calls invalidate packet pointers. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=51c39bb1d5d105a02e29aa7960f0a395086e6342 <f1692ee23dcaaddc24ba407b269707ee5df1301f || >=51c39bb1d5d105a02e29aa7960f0a395086e6342 <1c2244437f9ad3dd91215f920401a14f2542dbfc || >=51c39bb1d5d105a02e29aa7960f0a395086e6342 <1a4607ffba35bf2a630aab299e34dd3f6e658d70 | f1692ee23dcaaddc24ba407b269707ee5df1301f, 1c2244437f9ad3dd91215f920401a14f2542dbfc, 1a4607ffba35bf2a630aab299e34dd3f6e658d70 |
| Linux/Linuxgeneric | 5.6 | Not reported |
Published upstream
May 5, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet pointers Tail-called programs could execute any of the helpers that invalidate packet pointers. Hence, conservatively assume that each tail call invalidates packet pointers. Making the change in bpf_helper_changes_pkt_data() automatically makes use of check_cfg() logic that computes 'changes_pkt_data' effect for global sub-programs, such that the following program could be rejected: int tail_call(struct __sk_buff *sk) { bpf_tail_call_static(sk, &jmp_table, 0); return 0; } SEC("tc") int not_safe(struct __sk_buff *sk) { int *p = (void *)(long)sk->data; ... make p valid ... tail_call(sk); *p = 42; /* this is unsafe */ ... } The tc_bpf2bpf.c:subprog_tc() needs change: mark it as a function that can invalidate packet pointers. Otherwise, it can't be freplaced with tailcall_freplace.c:entry_freplace() that does a tail call.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-58237 records a Unknown severity vulnerability in bpf: consider that tail calls invalidate packet pointers. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=51c39bb1d5d105a02e29aa7960f0a395086e6342 <f1692ee23dcaaddc24ba407b269707ee5df1301f || >=51c39bb1d5d105a02e29aa7960f0a395086e6342 <1c2244437f9ad3dd91215f920401a14f2542dbfc || >=51c39bb1d5d105a02e29aa7960f0a395086e6342 <1a4607ffba35bf2a630aab299e34dd3f6e658d70 | f1692ee23dcaaddc24ba407b269707ee5df1301f, 1c2244437f9ad3dd91215f920401a14f2542dbfc, 1a4607ffba35bf2a630aab299e34dd3f6e658d70 |
| Linux/Linuxgeneric | 5.6 | Not reported |
Published upstream
May 5, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: consider that tail calls invalidate packet pointers Tail-called programs could execute any of the helpers that invalidate packet pointers. Hence, conservatively assume that each tail call invalidates packet pointers. Making the change in bpf_helper_changes_pkt_data() automatically makes use of check_cfg() logic that computes 'changes_pkt_data' effect for global sub-programs, such that the following program could be rejected: int tail_call(struct __sk_buff *sk) { bpf_tail_call_static(sk, &jmp_table, 0); return 0; } SEC("tc") int not_safe(struct __sk_buff *sk) { int *p = (void *)(long)sk->data; ... make p valid ... tail_call(sk); *p = 42; /* this is unsafe */ ... } The tc_bpf2bpf.c:subprog_tc() needs change: mark it as a function that can invalidate packet pointers. Otherwise, it can't be freplaced with tailcall_freplace.c:entry_freplace() that does a tail call.
Quoted source text, attributed separately from HOL analysis.