cbcvebase.
CVE-2024-49949
published 2024-10-21

CVE-2024-49949: In the Linux kernel, the following vulnerability has been resolved: net: avoid potential underflow in qdisc_pkt_len_init() with UFO After commit 7c6d2ecbda83…

PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.28%
20.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net: avoid potential underflow in qdisc_pkt_len_init() with UFO After commit 7c6d2ecbda83 ("net: be more gentle about silly gso requests coming from user") virtio_net_hdr_to_skb() had sanity check to detect malicious attempts from user space to cook a bad GSO packet. Then commit cf9acc90c80ec ("net: virtio_net_hdr_to_skb: count transport header in UFO") while fixing one issue, allowed user space to cook a GSO packet with the following characteristic : IPv4 SKB_GSO_UDP, gso_size=3, skb->len = 28. When this packet arrives in qdisc_pkt_len_init(), we end up with hdr_len = 28 (IPv4 header + UDP header), matching skb->len Then the following sets gso_segs to 0 : gso_segs = DIV_ROUND_UP(skb->len - hdr_len, shinfo->gso_size); Then later we set qdisc_skb_cb(skb)->pkt_len to back to zero :/ qdisc_skb_cb(skb)->pkt_len += (gso_segs - 1) * hdr_len; This leads to the following crash in fq_codel [1] qdisc_pkt_len_init() is best effort, we only want an estimation of the bytes sent on the wire, not crashing the kernel. This patch is fixing this particular issue, a following one adds more sanity checks for another potential bug. [1] [ 70.724101] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 70.724561] #PF: supervisor read access in kernel mode [ 70.724561] #PF: error_code(0x0000) - not-present page [ 70.724561] PGD 10ac61067 P4D 10ac61067 PUD 107ee2067 PMD 0 [ 70.724561] Oops: Oops: 0000 [#1] SMP NOPTI [ 70.724561] CPU: 11 UID: 0 PID: 2163 Comm: b358537762 Not tainted 6.11.0-virtme #991 [ 70.724561] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 70.724561] RIP: 0010:fq_codel_enqueue (net/sched/sch_fq_codel.c:120 net/sched/sch_fq_codel.c:168 net/sched/sch_fq_codel.c:230) sch_fq_codel [ 70.724561] Code: 24 08 49 c1 e1 06 44 89 7c 24 18 45 31 ed 45 31 c0 31 ff 89 44 24 14 4c 03 8b 90 01 00 00 eb 04 39 ca 73 37 4d 8b 39 83 c7 01 8b 17 49 89

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
debianlinux-6.1< linux 6.1.115-1 (bookworm)linux 6.1.115-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 0f810d06b507aa40fef8d1ac0a88e6d0590dbfc3 < 939c88cbdc668dadd8cfa7a35d9066331239041c939c88cbdc668dadd8cfa7a35d9066331239041c
linuxlinux>= 4.14.256 < 4.154.15
linuxlinux>= 4.19.218 < 4.19.3234.19.323
linuxlinux>= 5.10.82 < 5.10.2275.10.227
linuxlinux>= 5.15.5 < 5.15.1685.15.168
linuxlinux>= 5.4.162 < 5.4.2855.4.285
linuxlinux>= 8e6bae950da9dc2d2c6c18b1c6b206dc00dc8772 < ba26060a29d3ca1bfc737aa79f7125128f35147cba26060a29d3ca1bfc737aa79f7125128f35147c
linuxlinux>= 960b360ca7463921c1a6b72e7066a706d6406223 < d70ca7598943572d5e384227bd268acb5109bf72d70ca7598943572d5e384227bd268acb5109bf72
linuxlinux>= cf9acc90c80ecbee00334aa85d92f4e74014bcff < d6114993e0a89fde84a60a60a8329a571580b174d6114993e0a89fde84a60a60a8329a571580b174
linuxlinux>= cf9acc90c80ecbee00334aa85d92f4e74014bcff < 25ab0b87dbd89cecef8a9c60a02bb97832e471d125ab0b87dbd89cecef8a9c60a02bb97832e471d1
linuxlinux>= cf9acc90c80ecbee00334aa85d92f4e74014bcff < f959cce8a2a04ce776aa8b78e83ce339e0d7fbacf959cce8a2a04ce776aa8b78e83ce339e0d7fbac
linuxlinux>= cf9acc90c80ecbee00334aa85d92f4e74014bcff < 81fd007dcd47c34471766249853e4d4bce8eea4b81fd007dcd47c34471766249853e4d4bce8eea4b
linuxlinux>= cf9acc90c80ecbee00334aa85d92f4e74014bcff < c20029db28399ecc50e556964eaba75c43b1e2f1c20029db28399ecc50e556964eaba75c43b1e2f1
linuxlinux>= fb2dbc124a7f800cd0e4f901a1bbb769a017104c < 1598d70ad9c7d0a4d9d54b82094e9f45908fda6d1598d70ad9c7d0a4d9d54b82094e9f45908fda6d
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.115-16.1.115-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 6.11.4-16.11.4-1
linuxlinux_kernel>= 0 < 5.4.0-208.2285.4.0-208.228
linuxlinux_kernel>= 0 < 5.15.0-127.1375.15.0-127.137

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.