CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of pointer spill metadata during the cleanup of dead stack slots, specifically when converting live low halves of STACK_SPILL slots. This flaw could allow unauthorized access to memory, bypassing critical checks for pointer spills, potentially leading to data corruption or exploitation. Organizations using affected Linux kernel versions should prioritize this issue to mitigate risks associated with memory safety and integrity.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve pointer spill metadata during half-slot cleanup __clean_func_state() cleans dead stack slots in 4-byte halves. When the high half of a STACK_SPILL slot is dead and the low half remains live, cleanup converts the live low half to STACK_MISC or STACK_ZERO and clears the saved spilled_ptr metadata. That conversion is safe only for scalar spills. For a pointer spill, this metadata clear lets a later 32-bit fill from the still-live half avoid the normal non-scalar register-fill check and be treated as an ordinary scalar stack read. Leave non-scalar spill slots intact in this half-live shape. This is conservative for pruning and preserves the existing check_stack_read_fixed_off() rejection path for partial fills from pointer spills.