CVE-2024-41009 is a memory-safety vulnerability in the Linux kernel BPF ring buffer reservation logic. The ring buffer exposes a writable consumer_pos counter to user space and maps its circular data area twice contiguously in virtual memory. Manipulating consumer_pos can bypass the reservation-size check, allowing a subsequent reservation to overlap an outstanding record and expose its normally inaccessible header to modification by a BPF program. Corrupting the header's pg_off field causes bpf_ringbuf_submit() or bpf_ringbuf_discard() to restore an incorrect ring buffer pointer, potentially making bpf_ringbuf_commit() reference the wrong page and crash the kernel.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel BPF ring-buffer vulnerability permits overlapping record reservations when the user-writable consumer position is manipulated. A BPF program can then corrupt another record's bookkeeping header, potentially causing a kernel crash and denial of service. The reference assigns a CVSS v3 base score of 5.5, with local access and low privileges required.
Linux kernel BPF ring-buffer issue involving reservation overruns.
Linux kernel BPF ring-buffer issue involving reservation overruns.
Linux kernel BPF ring-buffer reservation overrun vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.