cbcvebase.
CVE-2024-57996
published 2025-02-27

CVE-2024-57996: In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: don't allow 1 packet limit The current implementation does not work…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
17.0th percentile
In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: don't allow 1 packet limit The current implementation does not work correctly with a limit of 1. iproute2 actually checks for this and this patch adds the check in kernel as well. This fixes the following syzkaller reported crash: UBSAN: array-index-out-of-bounds in net/sched/sch_sfq.c:210:6 index 65535 is out of range for type 'struct sfq_head[128]' CPU: 0 PID: 2569 Comm: syz-executor101 Not tainted 5.10.0-smp-DEV #1 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Call Trace: __dump_stack lib/dump_stack.c:79 [inline] dump_stack+0x125/0x19f lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:148 [inline] __ubsan_handle_out_of_bounds+0xed/0x120 lib/ubsan.c:347 sfq_link net/sched/sch_sfq.c:210 [inline] sfq_dec+0x528/0x600 net/sched/sch_sfq.c:238 sfq_dequeue+0x39b/0x9d0 net/sched/sch_sfq.c:500 sfq_reset+0x13/0x50 net/sched/sch_sfq.c:525 qdisc_reset+0xfe/0x510 net/sched/sch_generic.c:1026 tbf_reset+0x3d/0x100 net/sched/sch_tbf.c:319 qdisc_reset+0xfe/0x510 net/sched/sch_generic.c:1026 dev_reset_queue+0x8c/0x140 net/sched/sch_generic.c:1296 netdev_for_each_tx_queue include/linux/netdevice.h:2350 [inline] dev_deactivate_many+0x6dc/0xc20 net/sched/sch_generic.c:1362 __dev_close_many+0x214/0x350 net/core/dev.c:1468 dev_close_many+0x207/0x510 net/core/dev.c:1506 unregister_netdevice_many+0x40f/0x16b0 net/core/dev.c:10738 unregister_netdevice_queue+0x2be/0x310 net/core/dev.c:10695 unregister_netdevice include/linux/netdevice.h:2893 [inline] __tun_detach+0x6b6/0x1600 drivers/net/tun.c:689 tun_detach drivers/net/tun.c:705 [inline] tun_chr_close+0x104/0x1b0 drivers/net/tun.c:3640 __fput+0x203/0x840 fs/file_table.c:280 task_work_run+0x129/0x1b0 kernel/task_work.c:185 exit_task_work include/linux/task_work.h:33 [inline] do_exit+0x5ce/0x2200 kernel/exit.c:931 do_group_exit+0x144/0x310 kernel/exit.c:1046 __do_sys_exit_group kernel/exit.c:1057 [inline] __se

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e12f6013d0a69660e8b99bfe381b9546ae667328e12f6013d0a69660e8b99bfe381b9546ae667328
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1e6d9d87626cf89eeffb4d943db12cb5b10bf9611e6d9d87626cf89eeffb4d943db12cb5b10bf961
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1b562b7f9231432da40d12e19786c1bd7df653a71b562b7f9231432da40d12e19786c1bd7df653a7
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 35d0137305ae2f97260a9047f445bd4434bd6cc735d0137305ae2f97260a9047f445bd4434bd6cc7
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 833e9a1c27b82024db7ff5038a51651f48f05e5e833e9a1c27b82024db7ff5038a51651f48f05e5e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7d8947f2153ee9c5ab4cb17861a11cc45f30e8c47d8947f2153ee9c5ab4cb17861a11cc45f30e8c4
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7fefc294204f10a3405f175f4ac2be16d63f135e7fefc294204f10a3405f175f4ac2be16d63f135e
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 10685681bafce6febb39770f3387621bf5d67d0b10685681bafce6febb39770f3387621bf5d67d0b
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.15.0-153.1635.15.0-153.163
linuxlinux_kernel>= 0 < 6.8.0-79.796.8.0-79.79
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 0 < 4.4.0-272.3064.4.0-272.306
linuxlinux_kernel>= 0 < 4.15.0-241.2534.15.0-241.253
linuxlinux_kernel>= 0 < 5.4.0-221.2415.4.0-221.241
linuxlinux_kernel>= 2.6.12 < 6.1.1296.1.129
linuxlinux_kernel>= 6.13 < 6.13.26.13.2
linuxlinux_kernel>= 6.2 < 6.6.766.6.76
linuxlinux_kernel>= 6.7 < 6.12.136.12.13

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.4HIGH
vendor_ubuntu8.4HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.