CyberRota Analysis
AI-GeneratedThe vulnerability in the Linux kernel affects the cls_bpf classifier, allowing device-bound programs to be incorrectly attached to different network devices without proper verification. This can lead to instability, including potential system panics if the original device is deleted while the program remains attached to another device. Network administrators and developers utilizing the Linux kernel for networking applications should prioritize addressing this issue to maintain system integrity and prevent unexpected failures.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: reject dev-bound programs bound to a different device cls_bpf_prog_from_efd() obtained a SCHED_CLS program via bpf_prog_get_type_dev() but never verified that a device-bound (offloaded) program's bound netdev matches the TC netdev the classifier is being attached to. This let a program loaded with prog_ifindex for device A be attached via cls_bpf + skip_sw to device B; deleting device A then destroyed the program's offload state while it was still attached to device B, triggering a netdevsim WARN (panic with panic_on_warn=1). Mirror the XDP attach path (net/core/dev.c) and reject the attach with -EINVAL when a dev-bound program's bound device does not match the target device.