CVE-2024-56372: net: tun: fix tun_napi_alloc_frags()

Published Jan 11, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: tun: fix tunnapiallocfrags()

syzbot reported the following crash [1]

Issue came with the blamed commit. Instead of going through all the iov components, we keep using the first one and end up with a malformed skb.

[1]

kernel BUG at net/core/skbuff.c:2849 ! Oops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI CPU: 0 UID: 0 PID: 6230 Comm: syz-executor132 Not tainted 6.13.0-rc1-syzkaller-00407-g96b6fcc0ee41 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/25/2024 RIP: 0010:pskbpulltail+0x1568/0x1570 net/core/skbuff.c:2848 Code: 38 c1 0f 8c 32 f1 ff ff 4c 89 f7 e8 92 96 74 f8 e9 25 f1 ff ff e8 e8 ae 09 f8 48 8b 5c 24 08 e9 eb fb ff ff e8 d9 ae 09 f8 90 <0f> 0b 66 0f 1f 44 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 RSP: 0018:ffffc90004cbef30 EFLAGS: 00010293 RAX: ffffffff8995c347 RBX: 00000000fffffff2 RCX: ffff88802cf45a00 RDX: 0000000000000000 RSI: 00000000fffffff2 RDI: 0000000000000000 RBP: ffff88807df0c06a R08: ffffffff8995b084 R09: 1ffff1100fbe185c R10: dffffc0000000000 R11: ffffed100fbe185d R12: ffff888076e85d50 R13: ffff888076e85c80 R14: ffff888076e85cf4 R15: ffff888076e85c80 FS: 00007f0dca6ea6c0(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f0dca6ead58 CR3: 00000000119da000 CR4: 00000000003526f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> skbcowdata+0x2da/0xcb0 net/core/skbuff.c:5284 tipcaeaddecrypt net/tipc/crypto.c:894 [inline] tipccryptorcv+0x402/0x24e0 net/tipc/crypto.c:1844 tipcrcv+0x57e/0x12a0 net/tipc/node.c:2109 tipcl2rcvmsg+0x2bd/0x450 net/tipc/bearer.c:668 netifreceiveskblistptype net/core/dev.c:5720 [inline] netifreceiveskblistcore+0x8b7/0x980 net/core/dev.c:5762 netifreceiveskblist net/core/dev.c:5814 [inline] netifreceiveskblistinternal+0xa51/0xe30 net/core/dev.c:5905 gronormallist include/net/gro.h:515 [inline] napicompletedone+0x2b5/0x870 net/core/dev.c:6256 napicomplete include/linux/netdevice.h:567 [inline] tungetuser+0x2ea0/0x4890 drivers/net/tun.c:1982 tunchrwriteiter+0x10d/0x1f0 drivers/net/tun.c:2057 doiterreadvwritev+0x600/0x880 vfswritev+0x376/0xba0 fs/readwrite.c:1050 dowritev+0x1b6/0x360 fs/readwrite.c:1096 dosyscallx64 arch/x86/entry/common.c:52 [inline] dosyscall64+0xf3/0x230 arch/x86/entry/common.c:83 entrySYSCALL64afterhwframe+0x77/0x7f

Other sources

This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.

Launchpad

Affected Software

7 affected componentsFixes available
Linux Kernel
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.27-1
Linux Linux kernel>=6.4<6.6.68
Linux Linux kernel>=6.7<6.12.7
Linux Linux kernel=6.13-rc1
Linux Linux kernel=6.13-rc2
Linux Linux kernel=6.13-rc3

Event History

Jan 11, 2025
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
Description
Data Sourced
via NVD·01:15 PM
Description
Data Sourced
via NVD·01:15 PM
RemedySeverityWeaknessAffected Software
Apr 8, 2025
Data Sourced
via Launchpad·06:46 PM
Description
May 2, 2025
Data Sourced
via Ubuntu·06:51 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-56372?

CVE-2024-56372 is categorized as a moderate severity vulnerability in the Linux kernel.

2

How do I fix CVE-2024-56372?

To fix CVE-2024-56372, update your Linux kernel to the latest version that includes the necessary patches.

3

What causes CVE-2024-56372?

CVE-2024-56372 is caused by a flaw in the tun_napi_alloc_frags() function in the Linux kernel that mishandles I/O vector components.

4

Which versions of the Linux kernel are affected by CVE-2024-56372?

CVE-2024-56372 affects multiple versions of the Linux kernel prior to the patch that resolves the issue.

5

How can I determine if my system is vulnerable to CVE-2024-56372?

You can determine if your system is vulnerable to CVE-2024-56372 by checking your kernel version against security advisories or vulnerability databases.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203