PT-2024-7193 · Linux+6 · Linux Kernel+6

Eric Dumazet

+1

·

Published

2024-06-17

·

Updated

2025-09-29

·

CVE-2024-44940

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the function gue gro receive() in the Linux kernel, which has a problem with incorrect input validation. This can potentially impact the confidentiality, integrity, and availability of protected information. The vulnerability is related to the handling of unsupported protocols in the gue gro receive() function. A packet can be easily constructed to trigger a warning, which was previously reduced from WARN ON to WARN ON ONCE. The warning has been removed as it is expected and not actionable.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2024-13260
ALT-PU-2024-13979
ALT-PU-2024-14046
AZL-49140
BDU:2024-08532
CVE-2024-44940
DLA-4008-1
DLA-4075-1
DSA-5782-1
MGASA-2024-0309
MGASA-2024-0310
OESA-2024-2124
OESA-2024-2255
OESA-2024-2257
OESA-2024-2258
USN-7069-1
USN-7069-2
USN-7110-1
USN-7154-1
USN-7154-2
USN-7155-1
USN-7156-1
USN-7159-1
USN-7159-2
USN-7159-3
USN-7159-4
USN-7159-5
USN-7166-1
USN-7166-2
USN-7166-3
USN-7166-4
USN-7186-1
USN-7186-2
USN-7194-1
USN-7195-1
USN-7195-2
USN-7196-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu