CVE-2024-49947: net: test for not too small csum_start in virtio_net_hdr_to_skb()

Published Oct 21, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: test for not too small csumstart in virtionethdrtoskb()

syzbot was able to trigger this warning [1], after injecting a malicious packet through afpacket, setting skb->csumstart and thus the transport header to an incorrect value.

We can at least make sure the transport header is after the end of the network header (with a estimated minimal size).

[1] [ 67.873027] skb len=4096 headroom=16 headlen=14 tailroom=0 mac=(-1,-1) maclen=0 net=(16,-6) trans=10 shinfo(txflags=0 nrfrags=1 gso(size=0 type=0 segs=0)) csum(0xa start=10 offset=0 ipsummed=3 completesw=0 valid=0 level=0) hash(0x0 sw=0 l4=0) proto=0x0800 pkttype=0 iif=0 priority=0x0 mark=0x0 alloccpu=10 vlanall=0x0 encapsulation=0 inner(proto=0x0000, mac=0, net=0, trans=0) [ 67.877172] dev name=veth0vlan feat=0x000061164fdd09e9 [ 67.877764] sk family=17 type=3 proto=0 [ 67.878279] skb linear: 00000000: 00 00 10 00 00 00 00 00 0f 00 00 00 08 00 [ 67.879128] skb frag: 00000000: 0e 00 07 00 00 00 28 00 08 80 1c 00 04 00 00 02 [ 67.879877] skb frag: 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.880647] skb frag: 00000020: 00 00 02 00 00 00 08 00 1b 00 00 00 00 00 00 00 [ 67.881156] skb frag: 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.881753] skb frag: 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.882173] skb frag: 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.882790] skb frag: 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.883171] skb frag: 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.883733] skb frag: 00000080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.884206] skb frag: 00000090: 00 00 00 00 00 00 00 00 00 00 69 70 76 6c 61 6e [ 67.884704] skb frag: 000000a0: 31 00 00 00 00 00 00 00 00 00 2b 00 00 00 00 00 [ 67.885139] skb frag: 000000b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.885677] skb frag: 000000c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.886042] skb frag: 000000d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.886408] skb frag: 000000e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.887020] skb frag: 000000f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.887384] skb frag: 00000100: 00 00 [ 67.887878] ------------[ cut here ]------------ [ 67.887908] offset (-6) >= skbheadlen() (14) [ 67.888445] WARNING: CPU: 10 PID: 2088 at net/core/dev.c:3332 skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.889353] Modules linked in: macsec macvtap macvlan hsr wireguard curve25519x8664 libcurve25519generic libchacha20poly1305 chachax8664 libchacha poly1305x8664 dummy bridge srmod cdrom evdev pcspkr i2cpiix4 9pnetvirtio 9p 9pnet netfs [ 67.890111] CPU: 10 UID: 0 PID: 2088 Comm: b363492833 Not tainted 6.11.0-virtme #1011 [ 67.890183] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 67.890309] RIP: 0010:skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.891043] Call Trace: [ 67.891173] <TASK> [ 67.891274] ? warn (kernel/panic.c:741) [ 67.891320] ? skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.891333] ? reportbug (lib/bug.c:180 lib/bug.c:219) [ 67.891348] ? handlebug (arch/x86/kernel/traps.c:239) [ 67.891363] ? excinvalidop (arch/x86/kernel/traps.c:260 (discriminator 1)) [ 67.891372] ? asmexcinvalidop (./arch/x86/include/asm/idtentry.h:621) [ 67.891388] ? skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.891399] ? skbchecksumhelp (net/core/dev.c:3332 (discriminator 2)) [ 67.891416] ipdofragment (net/ipv4/ipoutput.c:777 (discriminator 1)) [ 67.891448] ? iplocalout (./include/linux/skbuff.h:1146 ./include/net/l3mdev.h:196 ./include/net/l3mdev.h:213 ne ---truncated---

Other sources

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

5 affected componentsFixes available
Linux Linux kernel>=6.6.14<6.6.55
Linux Linux kernel>=6.8<6.10.14
Linux Linux kernel>=6.11<6.11.3
Linux Linux kernel=6.12-rc1
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.22-16.12.25-1

Event History

Oct 21, 2024
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
Description
Feb 20, 2025
Data Sourced
via Launchpad·12:45 AM
Description
Apr 5, 2025
Data Sourced
via Ubuntu·12:54 AM
RemedyDescriptionSeverityAffected Software
Apr 13, 2025
Data Sourced
via Debian·12:56 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-49947?

CVE-2024-49947 has not been assigned a specific CVSS score yet, but it is considered a significant vulnerability in the Linux kernel.

2

How do I fix CVE-2024-49947?

To resolve CVE-2024-49947, upgrade the Linux kernel to a version that is not affected by this vulnerability.

3

Which versions of the Linux kernel are affected by CVE-2024-49947?

CVE-2024-49947 affects specific versions of the Linux kernel including 6.6.14 to 6.6.55, 6.8 to 6.10.14, and 6.11 to 6.11.3.

4

What type of vulnerability is CVE-2024-49947?

CVE-2024-49947 is a vulnerability in the Linux kernel related to the handling of malicious packets in the network stack.

5

Is there a workaround for CVE-2024-49947?

Currently, there is no documented workaround for CVE-2024-49947; updating the kernel is the recommended course of action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203