cbcvebase.
CVE-2024-37356
published 2024-06-21

CVE-2024-37356: In the Linux kernel, the following vulnerability has been resolved: tcp: Fix shift-out-of-bounds in dctcp_update_alpha(). In dctcp_update_alpha(), we use a…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.1th percentile
In the Linux kernel, the following vulnerability has been resolved:

tcp: Fix shift-out-of-bounds in dctcp_update_alpha().

In dctcp_update_alpha(), we use a module parameter dctcp_shift_g
as follows:

alpha -= min_not_zero(alpha, alpha >> dctcp_shift_g);
...
delivered_ce /sys/module/tcp_dctcp/parameters/dctcp_shift_g
# cat /sys/module/tcp_dctcp/parameters/dctcp_shift_g
10
# echo 11 > /sys/module/tcp_dctcp/parameters/dctcp_shift_g
-bash: echo: write error: Invalid argument

[0]:
UBSAN: shift-out-of-bounds in net/ipv4/tcp_dctcp.c:143:12
shift exponent 100 is too large for 32-bit type 'u32' (aka 'unsigned int')
CPU: 0 PID: 8083 Comm: syz-executor345 Not tainted 6.9.0-05151-g1b294a1f3561 #2
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
1.13.0-1ubuntu1.1 04/01/2014
Call Trace:

__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0x201/0x300 lib/dump_stack.c:114
ubsan_epilogue lib/ubsan.c:231 [inline]
__ubsan_handle_shift_out_of_bounds+0x346/0x3a0 lib/ubsan.c:468
dctcp_update_alpha+0x540/0x570 net/ipv4/tcp_dctcp.c:143
tcp_in_ack_event net/ipv4/tcp_input.c:3802 [inline]
tcp_ack+0x17b1/0x3bc0 net/ipv4/tcp_input.c:3948
tcp_rcv_state_process+0x57a/0x2290 net/ipv4/tcp_input.c:6711
tcp_v4_do_rcv+0x764/0xc40 net/ipv4/tcp_ipv4.c:1937
sk_backlog_rcv include/net/sock.h:1106 [inline]
__release_sock+0x20f/0x350 net/core/sock.c:2983
release_sock+0x61/0x1f0 net/core/sock.c:3549
mptcp_subflow_shutdown+0x3d0/0x620 net/mptcp/protocol.c:2907
mptcp_check_send_data_fin+0x225/0x410 net/mptcp/protocol.c:2976
__mptcp_close+0x238/0xad0 net/mptcp/protocol.c:3072
mptcp_close+0x2a/0x1a0 net/mptcp/protocol.c:3127
inet_release+0x190/0x1f0 net/ipv4/af_inet.c:437
__sock_release net/socket.c:659 [inline]
sock_close+0xc0/0x240 net/socket.c:1421
__fput+0x41b/0x890 fs/file_table.c:422
task_work_run+0x23b/0x300 kernel/task_work.c:180
exit_task_work include/linux/task_work.h:38 [inline]
do_exit+0x9c8/0x2540 kernel/exit.c:878
do_group_exit+0x201/0x2b0 kernel/exit.c:1027
__do_sys_exit_group

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.94-1 (bookworm)linux 6.1.94-1 (bookworm)
linuxlinux
linuxlinux>= e3118e8359bb7c59555aca60c725106e6d78c5ce < 06d0fe049b51b0a92a70df8333fd85c4ba3eb2c606d0fe049b51b0a92a70df8333fd85c4ba3eb2c6
linuxlinux>= e3118e8359bb7c59555aca60c725106e6d78c5ce < 6aacaa80d962f4916ccf90e2080306cec6c90fcf6aacaa80d962f4916ccf90e2080306cec6c90fcf
linuxlinux>= e3118e8359bb7c59555aca60c725106e6d78c5ce < e9b2f60636d18dfd0dd4965b3316f88dfd6a2b31e9b2f60636d18dfd0dd4965b3316f88dfd6a2b31
linuxlinux>= e3118e8359bb7c59555aca60c725106e6d78c5ce < 8602150286a2a860a1dc55cbd04f99316f19b40a8602150286a2a860a1dc55cbd04f99316f19b40a
linuxlinux>= e3118e8359bb7c59555aca60c725106e6d78c5ce < e65d13ec00a738fa7661925fd5929ab3c765d4bee65d13ec00a738fa7661925fd5929ab3c765d4be
linuxlinux>= e3118e8359bb7c59555aca60c725106e6d78c5ce < 02261d3f9dc7d1d7be7d778f839e3404ab99034c02261d3f9dc7d1d7be7d778f839e3404ab99034c
linuxlinux>= e3118e8359bb7c59555aca60c725106e6d78c5ce < 237340dee373b97833a491d2e99fcf1d4a9adafd237340dee373b97833a491d2e99fcf1d4a9adafd
linuxlinux>= e3118e8359bb7c59555aca60c725106e6d78c5ce < 3ebc46ca8675de6378e3f8f40768e180bb8afa663ebc46ca8675de6378e3f8f40768e180bb8afa66
linuxlinux_kernel>= 0 < 5.10.221-15.10.221-1
linuxlinux_kernel>= 0 < 6.1.94-16.1.94-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 6.9.7-16.9.7-1
linuxlinux_kernel>= 0 < 5.4.0-192.2125.4.0-192.212
linuxlinux_kernel>= 0 < 5.15.0-121.1315.15.0-121.131
linuxlinux_kernel>= 0 < 6.8.0-44.446.8.0-44.44
linuxlinux_kernel>= 3.18 < 4.19.3164.19.316
linuxlinux_kernel>= 4.20 < 5.4.2785.4.278
linuxlinux_kernel>= 5.11 < 5.15.1615.15.161
linuxlinux_kernel>= 5.16 < 6.1.936.1.93
linuxlinux_kernel>= 5.5 < 5.10.2195.10.219
linuxlinux_kernel>= 6.2 < 6.6.336.6.33
linuxlinux_kernel>= 6.7 < 6.9.46.9.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.