CVE-2024-49979
Description
In the Linux kernel, the following vulnerability has been resolved:
net: gso: fix tcp fraglist segmentation after pull from frag_list
Detect tcp gso fraglist skbs with corrupted geometry (see below) and pass these to skb_segment instead of skb_segment_list, as the first can segment them correctly.
Valid SKB_GSO_FRAGLIST skbs - consist of two or more segments - the head_skb holds the protocol headers plus first gso_size - one or more frag_list skbs hold exactly one segment - all but the last must be gso_size
Optional datapath hooks such as NAT and BPF (bpf_skb_pull_data) can modify these skbs, breaking these invariants.
In extreme cases they pull all data into skb linear. For TCP, this causes a NULL ptr deref in __tcpv4_gso_segment_list_csum at tcp_hdr(seg->next).
Detect invalid geometry due to pull, by checking head_skb size. Don't just drop, as this may blackhole a destination. Convert to be able to pass to regular skb_segment.
Approach and description based on a patch by Willem de Bruijn.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- osv-coords11 versionspkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:linux/kernelpkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:rpm/opensuse/kernel-source&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/kernel-source-longterm&distro=openSUSE%20Tumbleweedpkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]?arch=source&distro=oracular
< 6.11.0-1008.8+ 10 more
- (no CPE)range: < 6.11.0-1008.8
- (no CPE)range: >= 6.10.0, < 6.10.14
- (no CPE)range: < 6.11.0-1011.12
- (no CPE)range: < 6.11.8-1.1
- (no CPE)range: < 6.12.11-1.1
- (no CPE)range: < 6.11.0-1010.11
- (no CPE)range: < 6.11.0-18.18
- (no CPE)range: < 6.11.0-1009.10
- (no CPE)range: < 6.11.0-1009.9
- (no CPE)range: < 6.11.0-1009.9
- (no CPE)range: < 6.11.0-1005.5
Patches
Vulnerability mechanics
References
5- git.kernel.org/stable/c/17bd3bd82f9f79f3feba15476c2b2c95a9b11ff8nvdPatch
- git.kernel.org/stable/c/2d4a83a44428de45bfe9dccb0192a3711d1097e0nvdPatch
- git.kernel.org/stable/c/3fdd8c83e83fa5e82f1b5585245c51e0355c9f46nvdPatch
- git.kernel.org/stable/c/75733986fcb0725c0033cde94764389e287b331envd
- git.kernel.org/stable/c/e19201b0c67da5146eaac06fd3d44bd7945c3448nvd
News mentions
0No linked articles in our index yet.