PT-2024-30755 · Linux+4 · Linux Kernel+4

Published

2024-07-30

·

Updated

2025-09-29

·

CVE-2024-43897

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, which involves dropping bad GSO csum start and offset in virtio net hdr. The function already checks that a checksum requested with VIRTIO NET HDR F NEEDS CSUM is in skb linear, but for GSO packets, this might not hold for segs after segmentation. Syzkaller demonstrated to reach this warning in skb checksum help by injecting a TSO packet. The geometry of the bad input packet at tcp gso segment is provided. To mitigate this, stricter input validation is required. For GSO packets, the correct value of csum offset should be deduced from gso type, and for csum start, the real offset requires parsing to the transport header using existing segmentation parsing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-11863
ALT-PU-2024-12053
ALT-PU-2024-13121
ALT-PU-2024-14046
AZL-48670
BDU:2025-01922
CVE-2024-43897
DLA-4008-1
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2124
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4376-1
SUSE-SU-2024:3194-1
SUSE-SU-2024:3195-1
SUSE-SU-2024:3383-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2025:20044-1
SUSE-SU-2025:20047-1

Affected Products

Alt Linux
Astra Linux
Linux Kernel
Red Os
Suse