cbcvebase.
CVE-2024-58099
published 2025-04-29

CVE-2024-58099: In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.2th percentile
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame Andrew and Nikolay reported connectivity issues with Cilium's service load-balancing in case of vmxnet3. If a BPF program for native XDP adds an encapsulation header such as IPIP and transmits the packet out the same interface, then in case of vmxnet3 a corrupted packet is being sent and subsequently dropped on the path. vmxnet3_xdp_xmit_frame() which is called e.g. via vmxnet3_run_xdp() through vmxnet3_xdp_xmit_back() calculates an incorrect DMA address: page = virt_to_page(xdpf->data); tbi->dma_addr = page_pool_get_dma_addr(page) + VMXNET3_XDP_HEADROOM; dma_sync_single_for_device(&adapter->pdev->dev, tbi->dma_addr, buf_size, DMA_TO_DEVICE); The above assumes a fixed offset (VMXNET3_XDP_HEADROOM), but the XDP BPF program could have moved xdp->data. While the passed buf_size is correct (xdpf->len), the dma_addr needs to have a dynamic offset which can be calculated as xdpf->data - (void *)xdpf, that is, xdp->data - xdp->data_hard_start.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.11.6-1 (forky)linux 6.11.6-1 (forky)
linuxlinux
linuxlinux>= 54f00cce11786742bd11e5e68c3bf85e6dc048c9 < 59ba6cdadb9c26b606a365eb9c9b25eb2052622d59ba6cdadb9c26b606a365eb9c9b25eb2052622d
linuxlinux>= 54f00cce11786742bd11e5e68c3bf85e6dc048c9 < f82eb34fb59a8fb96c19f4f492c20eb774140bb5f82eb34fb59a8fb96c19f4f492c20eb774140bb5
linuxlinux>= 54f00cce11786742bd11e5e68c3bf85e6dc048c9 < 4678adf94da4a9e9683817b246b58ce15fb817824678adf94da4a9e9683817b246b58ce15fb81782
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.11.6-16.11.6-1
linuxlinux_kernel>= 0 < 6.11.6-16.11.6-1
linuxlinux_kernel>= 6.6 < 6.6.596.6.59
linuxlinux_kernel>= 6.7 < 6.11.66.11.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.