cbcvebase.
CVE-2024-49948
published 2024-10-21

CVE-2024-49948: In the Linux kernel, the following vulnerability has been resolved: net: add more sanity checks to qdisc_pkt_len_init() One path takes care of SKB_GSO_DODGY…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: add more sanity checks to qdisc_pkt_len_init() One path takes care of SKB_GSO_DODGY, assuming skb->len is bigger than hdr_len. virtio_net_hdr_to_skb() does not fully dissect TCP headers, it only make sure it is at least 20 bytes. It is possible for an user to provide a malicious 'GSO' packet, total length of 80 bytes. - 20 bytes of IPv4 header - 60 bytes TCP header - a small gso_size like 8 virtio_net_hdr_to_skb() would declare this packet as a normal GSO packet, because it would see 40 bytes of payload, bigger than gso_size. We need to make detect this case to not underflow qdisc_skb_cb(skb)->pkt_len.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < d7d1a28f5dd57b4d83def876f8d7b4403bd37df9d7d1a28f5dd57b4d83def876f8d7b4403bd37df9
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < 473426a1d53a68dd1e718e6cd00d57936993fa6c473426a1d53a68dd1e718e6cd00d57936993fa6c
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < 566a931a1436d0e0ad13708ea55479b95426213c566a931a1436d0e0ad13708ea55479b95426213c
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < 2415f465730e48b6e38da1c7c097317bf5dd2d202415f465730e48b6e38da1c7c097317bf5dd2d20
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < 27a8fabc54d2f960d47bdfbebf2bdc6e8a92a4c427a8fabc54d2f960d47bdfbebf2bdc6e8a92a4c4
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < 9b0ee571d20a238a22722126abdfde61f1b2bdd09b0ee571d20a238a22722126abdfde61f1b2bdd0
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < ff1c3cadcf405ab37dd91418a62a7acecf3bc5e2ff1c3cadcf405ab37dd91418a62a7acecf3bc5e2
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < 1eebe602a8d8264a12e35e39d0645fa88dbbacdd1eebe602a8d8264a12e35e39d0645fa88dbbacdd
linuxlinux>= 1def9238d4aa2146924994aa4b7dc861f03b9362 < ab9a9a9e9647392a19e7a885b08000e89c86b535ab9a9a9e9647392a19e7a885b08000e89c86b535
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137
linuxlinux_kernel>= 0 < 6.8.0-54.566.8.0-54.56
linuxlinux_kernel>= 0 < 6.11.0-18.186.11.0-18.18
linuxlinux_kernel>= 0 < 4.4.0-267.3014.4.0-267.301
linuxlinux_kernel>= 0 < 4.15.0-236.2484.15.0-236.248
linuxlinux_kernel>= 3.9 < 4.19.3234.19.323
linuxlinux_kernel>= 4.20 < 5.4.2855.4.285

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.