cbcvebase.
CVE-2024-43897
published 2024-08-26

CVE-2024-43897: In the Linux kernel, the following vulnerability has been resolved: net: drop bad gso csum_start and offset in virtio_net_hdr Tighten csum_start and…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: net: drop bad gso csum_start and offset in virtio_net_hdr Tighten csum_start and csum_offset checks in virtio_net_hdr_to_skb for GSO packets. The function already checks that a checksum requested with VIRTIO_NET_HDR_F_NEEDS_CSUM is in skb linear. But for GSO packets this might not hold for segs after segmentation. Syzkaller demonstrated to reach this warning in skb_checksum_help offset = skb_checksum_start_offset(skb); ret = -EINVAL; if (WARN_ON_ONCE(offset >= skb_headlen(skb))) By injecting a TSO packet: WARNING: CPU: 1 PID: 3539 at net/core/dev.c:3284 skb_checksum_help+0x3d0/0x5b0 ip_do_fragment+0x209/0x1b20 net/ipv4/ip_output.c:774 ip_finish_output_gso net/ipv4/ip_output.c:279 [inline] __ip_finish_output+0x2bd/0x4b0 net/ipv4/ip_output.c:301 iptunnel_xmit+0x50c/0x930 net/ipv4/ip_tunnel_core.c:82 ip_tunnel_xmit+0x2296/0x2c70 net/ipv4/ip_tunnel.c:813 __gre_xmit net/ipv4/ip_gre.c:469 [inline] ipgre_xmit+0x759/0xa60 net/ipv4/ip_gre.c:661 __netdev_start_xmit include/linux/netdevice.h:4850 [inline] netdev_start_xmit include/linux/netdevice.h:4864 [inline] xmit_one net/core/dev.c:3595 [inline] dev_hard_start_xmit+0x261/0x8c0 net/core/dev.c:3611 __dev_queue_xmit+0x1b97/0x3c90 net/core/dev.c:4261 packet_snd net/packet/af_packet.c:3073 [inline] The geometry of the bad input packet at tcp_gso_segment: [ 52.003050][ T8403] skb len=12202 headroom=244 headlen=12093 tailroom=0 [ 52.003050][ T8403] mac=(168,24) mac_len=24 net=(192,52) trans=244 [ 52.003050][ T8403] shinfo(txflags=0 nr_frags=1 gso(size=1552 type=3 segs=0)) [ 52.003050][ T8403] csum(0x60000c7 start=199 offset=1536 ip_summed=3 complete_sw=0 valid=0 level=0) Mitigate with stricter input validation. csum_offset: for GSO packets, deduce the correct value from gso_type. This is already done for USO. Extend it to TSO. Let UFO be: udp[46]_ufo_fragment ignores these fields and always computes the checksum in software. csum_start: finding the re

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.106-3 (bookworm)linux 6.1.106-3 (bookworm)
debianlinux-6.1< linux 6.1.106-3 (bookworm)linux 6.1.106-3 (bookworm)
linuxlinux>= 27874ca77bd2b05a3779c7b3a5c75d8dd7f0b40f < 413e785a89f8bde0d4156a54b8ac2fa003c06756413e785a89f8bde0d4156a54b8ac2fa003c06756
linuxlinux>= 5.15.165 < 5.15.1675.15.167
linuxlinux>= 5b1997487a3f3373b0f580c8a20b56c1b64b0775 < f01c5e335fbb7fb612d40f14a3c02e2612a43d3bf01c5e335fbb7fb612d40f14a3c02e2612a43d3b
linuxlinux>= 6.1.103 < 6.1.1076.1.107
linuxlinux>= 6.10.3 < 6.10.56.10.5
linuxlinux>= 6.6.44 < 6.6.466.6.46
linuxlinux>= 90d41ebe0cd4635f6410471efc1dd71b33e894cf < 6772c4868a8e7ad5305957cdb834ce881793acb76772c4868a8e7ad5305957cdb834ce881793acb7
linuxlinux>= e269d79c7d35aa3808b1f3c1737d63dab504ddc8 < 89add40066f9ed9abe5f7f886fe5789ff7e0c50e89add40066f9ed9abe5f7f886fe5789ff7e0c50e
linuxlinux>= e9164903b8b303c34723177b02fe91e49e3c4cd7 < 2edbb3e8838c672cd7e247e47989df9d03fc66682edbb3e8838c672cd7e247e47989df9d03fc6668
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.106-36.1.106-3
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 0 < 6.10.6-16.10.6-1
linuxlinux_kernel>= 5.15.165 < 6.1.1076.1.107
linuxlinux_kernel>= 6.10.3 < 6.10.56.10.5
linuxlinux_kernel>= 6.6.44 < 6.6.466.6.46
msrccbl2_kernel_5.15.167.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.180.1-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.