CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of stack slot indices during nospec checks, specifically in the BPF (Berkeley Packet Filter) subsystem. This flaw can lead to improper sanitization of memory writes, potentially allowing an attacker to exploit the Spectre v4 vulnerability and access sensitive data. Organizations utilizing Linux systems, particularly those relying on BPF for network packet processing or other critical operations, should prioritize addressing this issue to mitigate potential security risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix stack slot index in nospec checks check_stack_write_fixed_off() computes the byte slot for a fixed-offset stack write as -off - 1, and records each written byte in slot_type[] with (slot - i) % BPF_REG_SIZE. The Spectre v4 sanitization pre-check uses slot_type[i] instead. For a 4-byte write at fp-8 after the lower half of fp-8 has been zeroed, the pre-check scans bytes 0..3 and sees STACK_ZERO while the actual write updates bytes 7..4. That can leave the second half-slot write without nospec_result even though the bytes being overwritten still require sanitization. Use the same slot index in the sanitization pre-check that the write path uses when updating slot_type[].