CVE-2024-49947: net: test for not too small csum_start in virtio_net_hdr_to_skb()
In the Linux kernel, the following vulnerability has been resolved:
net: test for not too small csumstart in virtionethdrtoskb()
syzbot was able to trigger this warning [1], after injecting a malicious packet through afpacket, setting skb->csumstart and thus the transport header to an incorrect value.
We can at least make sure the transport header is after the end of the network header (with a estimated minimal size).
[1] [ 67.873027] skb len=4096 headroom=16 headlen=14 tailroom=0 mac=(-1,-1) maclen=0 net=(16,-6) trans=10 shinfo(txflags=0 nrfrags=1 gso(size=0 type=0 segs=0)) csum(0xa start=10 offset=0 ipsummed=3 completesw=0 valid=0 level=0) hash(0x0 sw=0 l4=0) proto=0x0800 pkttype=0 iif=0 priority=0x0 mark=0x0 alloccpu=10 vlanall=0x0 encapsulation=0 inner(proto=0x0000, mac=0, net=0, trans=0) [ 67.877172] dev name=veth0vlan feat=0x000061164fdd09e9 [ 67.877764] sk family=17 type=3 proto=0 [ 67.878279] skb linear: 00000000: 00 00 10 00 00 00 00 00 0f 00 00 00 08 00 [ 67.879128] skb frag: 00000000: 0e 00 07 00 00 00 28 00 08 80 1c 00 04 00 00 02 [ 67.879877] skb frag: 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.880647] skb frag: 00000020: 00 00 02 00 00 00 08 00 1b 00 00 00 00 00 00 00 [ 67.881156] skb frag: 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.881753] skb frag: 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.882173] skb frag: 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.882790] skb frag: 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.883171] skb frag: 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.883733] skb frag: 00000080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.884206] skb frag: 00000090: 00 00 00 00 00 00 00 00 00 00 69 70 76 6c 61 6e [ 67.884704] skb frag: 000000a0: 31 00 00 00 00 00 00 00 00 00 2b 00 00 00 00 00 [ 67.885139] skb frag: 000000b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.885677] skb frag: 000000c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.886042] skb frag: 000000d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.886408] skb frag: 000000e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.887020] skb frag: 000000f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.887384] skb frag: 00000100: 00 00 [ 67.887878] ------------[ cut here ]------------ [ 67.887908] offset (-6) >= skbheadlen() (14) [ 67.888445] WARNING: CPU: 10 PID: 2088 at net/core/dev.c:3332 skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.889353] Modules linked in: macsec macvtap macvlan hsr wireguard curve25519x8664 libcurve25519generic libchacha20poly1305 chachax8664 libchacha poly1305x8664 dummy bridge srmod cdrom evdev pcspkr i2cpiix4 9pnetvirtio 9p 9pnet netfs [ 67.890111] CPU: 10 UID: 0 PID: 2088 Comm: b363492833 Not tainted 6.11.0-virtme #1011 [ 67.890183] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 67.890309] RIP: 0010:skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.891043] Call Trace: [ 67.891173] <TASK> [ 67.891274] ? warn (kernel/panic.c:741) [ 67.891320] ? skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.891333] ? reportbug (lib/bug.c:180 lib/bug.c:219) [ 67.891348] ? handlebug (arch/x86/kernel/traps.c:239) [ 67.891363] ? excinvalidop (arch/x86/kernel/traps.c:260 (discriminator 1)) [ 67.891372] ? asmexcinvalidop (./arch/x86/include/asm/idtentry.h:621) [ 67.891388] ? skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.891399] ? skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.891416] ipdofragment (net/ipv4/ipoutput.c:777 (discriminator 1)) [ 67.891448] ? iplocalout (./include/linux/skbuff.h:1146 ./include/net/l3mdev.h:196 ./include/net/l3mdev.h:213 ne ---truncated---
Other sources
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49947?
CVE-2024-49947 has not been assigned a specific CVSS score yet, but it is considered a significant vulnerability in the Linux kernel.
How do I fix CVE-2024-49947?
To resolve CVE-2024-49947, upgrade the Linux kernel to a version that is not affected by this vulnerability.
Which versions of the Linux kernel are affected by CVE-2024-49947?
CVE-2024-49947 affects specific versions of the Linux kernel including 6.6.14 to 6.6.55, 6.8 to 6.10.14, and 6.11 to 6.11.3.
What type of vulnerability is CVE-2024-49947?
CVE-2024-49947 is a vulnerability in the Linux kernel related to the handling of malicious packets in the network stack.
Is there a workaround for CVE-2024-49947?
Currently, there is no documented workaround for CVE-2024-49947; updating the kernel is the recommended course of action.