Stable 6.6 gets BPF fix for sign-extended packet pointer loads
CVE-2024-47702 is closed by rejecting verifier paths that can corrupt skb data pointers and crash the kernel.
The Linux 6.6 stable series is set to pick up a BPF verifier fix for CVE-2024-47702, a flaw that could crash the kernel when eBPF programs sign-extend loads of packet boundary fields.
Syzbot triggered the bug after earlier verifier work began handling sign-extended context member accesses. Loading __sk_buff fields such as data, data_end, or data_meta with a 32-bit sign extension could leave the resulting pointer invalid once the verifier rewrote the access. Bounds checks then ran against a broken address and the kernel failed at runtime.
Normal C patterns cast those fields through a long and stay safe. Explicit sign extension of the same pointers does not. Yonghong Song's fix makes the verifier reject sign-extended loads of those packet fields, so the bad path never reaches the kernel.
Sasha Levin queued the change for 6.6, noting it closes the CVE by refusing the loads that can turn packet pointers into invalid addresses. Systems running untrusted or poorly audited BPF that touch skb packet metadata are the ones that needed the guardrail.