PT-2024-30755 · Linux+4 · Linux Kernel+4
Published
2024-07-30
·
Updated
2025-09-29
·
CVE-2024-43897
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability in the Linux kernel has been resolved, which involves dropping bad GSO csum start and offset in virtio net hdr. The function already checks that a checksum requested with VIRTIO NET HDR F NEEDS CSUM is in skb linear, but for GSO packets, this might not hold for segs after segmentation. Syzkaller demonstrated to reach this warning in skb checksum help by injecting a TSO packet. The geometry of the bad input packet at tcp gso segment is provided. To mitigate this, stricter input validation is required. For GSO packets, the correct value of csum offset should be deduced from gso type, and for csum start, the real offset requires parsing to the transport header using existing segmentation parsing.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linux Kernel
Red Os
Suse