CVE-2024-41009 is an out-of-bounds memory-access flaw in the Linux kernel BPF ring-buffer implementation. A privileged local attacker can manipulate the consumer position and the ring buffer's double-mapped circular layout to obtain overlapping record reservations, then alter an earlier record header so that bpf_ringbuf_commit() accesses an incorrect page, potentially crashing the kernel. The weakness is associated with CWE-121, stack-based buffer overflow, and affects the handling of outstanding BPF ring-buffer records.
The upstream fix tracks the oldest pending record position and rejects reservations when the range of outstanding records would exceed the ring-buffer size. Red Hat rates the issue Moderate (CVSS 3.1: 4.4), requiring local high privileges and primarily enabling denial of service; NVD assigns 5.5, while CVE.org reports 7.8 with confidentiality and integrity impacts. Red Hat issued kernel updates for multiple RHEL 8 and RHEL 9 streams, including extended-support variants, and reports no qualifying mitigation beyond applying the updates.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2024:8856 for the RHEL 8 kernel and RHSA-2024:8870 for RHEL 8 kernel-rt, addressing CVE-2024-41009.
Red Hat issued RHSA-2024:6753 with kernel fixes for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat issued RHSA-2024:10771 for RHEL 9.4 Extended Update Support and RHSA-2024:10772 and RHSA-2024:10773 for RHEL 9.2 Extended Update Support kernel and kernel-rt packages.
Red Hat issued RHSA-2024:10262 for RHEL 8.8 Extended Update Support and RHSA-2024:10274 for RHEL 9, providing kernel fixes for the BPF ring-buffer vulnerability.
An out-of-bounds memory-access flaw in the Linux kernel BPF ring-buffer implementation allowed manipulated reservations to overlap an earlier record and potentially corrupt its header, enabling a local attacker to crash the kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcecwe.mitre.org
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.