5.5

CVE-2024-49568

net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg

In the Linux kernel, the following vulnerability has been resolved:

net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg

When receiving proposal msg in server, the fields v2_ext_offset/
eid_cnt/ism_gid_cnt in proposal msg are from the remote client
and can not be fully trusted. Especially the field v2_ext_offset,
once exceed the max value, there has the chance to access wrong
address, and crash may happen.

This patch checks the fields v2_ext_offset/eid_cnt/ism_gid_cnt
before using them.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.10 < 6.6.68
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.7
Linux ≫ Linux Kernel Version 6.13 Update rc1
Linux ≫ Linux Kernel Version 6.13 Update rc2
Linux ≫ Linux Kernel Version 6.13 Update rc3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.52% 0.416
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/295a92e3df32e72aff0f4bc25c310e349d07ffbf
Patch
https://git.kernel.org/stable/c/42f6beb2d5779429417b5f8115a4e3fa695d2a6c
Patch
https://git.kernel.org/stable/c/7863c9f3d24ba49dbead7e03dfbe40deb5888fdf
Patch
https://git.kernel.org/stable/c/49798283fce4c1a24fb1ba4c7c39127739535571
https://git.kernel.org/stable/c/690b9a8db9460d065785548e43fd6a02d247c1b7
https://git.kernel.org/stable/c/9cc0170ae646876aa5de2f0cad3066ce53e86f27