CVE-2024-43897

EUVD-2024-40547
In the Linux kernel, the following vulnerability has been resolved:

net: drop bad gso csum_start and offset in virtio_net_hdr

Tighten csum_start and csum_offset checks in virtio_net_hdr_to_skb
for GSO packets.

The function already checks that a checksum requested with
VIRTIO_NET_HDR_F_NEEDS_CSUM is in skb linear. But for GSO packets
this might not hold for segs after segmentation.

Syzkaller demonstrated to reach this warning in skb_checksum_help

	offset = skb_checksum_start_offset(skb);
	ret = -EINVAL;
	if (WARN_ON_ONCE(offset >= skb_headlen(skb)))

By injecting a TSO packet:

WARNING: CPU: 1 PID: 3539 at net/core/dev.c:3284 skb_checksum_help+0x3d0/0x5b0
 ip_do_fragment+0x209/0x1b20 net/ipv4/ip_output.c:774
 ip_finish_output_gso net/ipv4/ip_output.c:279 [inline]
 __ip_finish_output+0x2bd/0x4b0 net/ipv4/ip_output.c:301
 iptunnel_xmit+0x50c/0x930 net/ipv4/ip_tunnel_core.c:82
 ip_tunnel_xmit+0x2296/0x2c70 net/ipv4/ip_tunnel.c:813
 __gre_xmit net/ipv4/ip_gre.c:469 [inline]
 ipgre_xmit+0x759/0xa60 net/ipv4/ip_gre.c:661
 __netdev_start_xmit include/linux/netdevice.h:4850 [inline]
 netdev_start_xmit include/linux/netdevice.h:4864 [inline]
 xmit_one net/core/dev.c:3595 [inline]
 dev_hard_start_xmit+0x261/0x8c0 net/core/dev.c:3611
 __dev_queue_xmit+0x1b97/0x3c90 net/core/dev.c:4261
 packet_snd net/packet/af_packet.c:3073 [inline]

The geometry of the bad input packet at tcp_gso_segment:

[   52.003050][ T8403] skb len=12202 headroom=244 headlen=12093 tailroom=0
[   52.003050][ T8403] mac=(168,24) mac_len=24 net=(192,52) trans=244
[   52.003050][ T8403] shinfo(txflags=0 nr_frags=1 gso(size=1552 type=3 segs=0))
[   52.003050][ T8403] csum(0x60000c7 start=199 offset=1536
ip_summed=3 complete_sw=0 valid=0 level=0)

Mitigate with stricter input validation.

csum_offset: for GSO packets, deduce the correct value from gso_type.
This is already done for USO. Extend it to TSO. Let UFO be:
udp[46]_ufo_fragment ignores these fields and always computes the
checksum in software.

csum_start: finding the real offset requires parsing to the transport
header. Do not add a parser, use existing segmentation parsing. Thanks
to SKB_GSO_DODGY, that also catches bad packets that are hw offloaded.
Again test both TSO and USO. Do not test UFO for the above reason, and
do not test UDP tunnel offload.

GSO packet are almost always CHECKSUM_PARTIAL. USO packets may be
CHECKSUM_NONE since commit 10154dbded6d6 ("udp: Allow GSO transmit
from devices with no checksum offload"), but then still these fields
are initialized correctly in udp4_hwcsum/udp6_hwcsum_outgoing. So no
need to test for ip_summed == CHECKSUM_PARTIAL first.

This revises an existing fix mentioned in the Fixes tag, which broke
small packets with GSO offload, as detected by kselftests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
5.15.165 ≤
𝑥
< 6.1.107
linuxlinux_kernel
6.6.44 ≤
𝑥
< 6.6.46
linuxlinux_kernel
6.10.3 ≤
𝑥
< 6.10.5
linuxlinux_kernel
6.11:rc1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.148-1
fixed
bookworm (security)
6.1.158-1
fixed
bullseye
5.10.223-1
not-affected
bullseye (security)
5.10.247-1
fixed
forky
6.17.13-1
fixed
sid
6.17.13-1
fixed
trixie
6.12.57-1
fixed
trixie (security)
6.12.48-1
fixed
linux-6.1
bullseye (security)
6.1.158-1~deb11u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux-hwe
bionic
ignored
focal
dne
jammy
dne
noble
dne
xenial
not-affected
linux-hwe-5.4
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-hwe-5.8
focal
ignored
jammy
dne
noble
dne
linux-hwe-5.11
focal
ignored
jammy
dne
noble
dne
linux-hwe-5.13
focal
ignored
jammy
dne
noble
dne
linux-hwe-5.15
focal
not-affected
jammy
dne
noble
dne
linux-hwe-5.19
focal
dne
jammy
ignored
noble
dne
linux-hwe-6.2
focal
dne
jammy
ignored
noble
dne
linux-hwe-6.5
focal
dne
jammy
ignored
noble
dne
linux-hwe-6.8
focal
dne
jammy
not-affected
noble
dne
linux-hwe-edge
bionic
ignored
focal
dne
jammy
dne
noble
dne
xenial
ignored
linux-lts-xenial
focal
dne
jammy
dne
noble
dne
trusty
not-affected
linux-kvm
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
xenial
not-affected
linux-allwinner-5.19
focal
dne
jammy
ignored
noble
dne
linux-aws-5.0
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-aws-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-aws-5.4
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-aws-5.8
focal
ignored
jammy
dne
noble
dne
linux-aws-5.11
focal
ignored
jammy
dne
noble
dne
linux-aws-5.13
focal
ignored
jammy
dne
noble
dne
linux-aws-5.15
focal
not-affected
jammy
dne
noble
dne
linux-aws-5.19
focal
dne
jammy
ignored
noble
dne
linux-aws-6.2
focal
dne
jammy
ignored
noble
dne
linux-aws-6.5
focal
dne
jammy
ignored
noble
dne
linux-aws-hwe
focal
dne
jammy
dne
noble
dne
xenial
not-affected
linux-azure
bionic
ignored
focal
not-affected
jammy
not-affected
noble
not-affected
trusty
not-affected
xenial
not-affected
linux-azure-4.15
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-azure-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-azure-5.4
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-azure-5.8
focal
ignored
jammy
dne
noble
dne
linux-azure-5.11
focal
ignored
jammy
dne
noble
dne
linux-azure-5.13
focal
ignored
jammy
dne
noble
dne
linux-azure-5.15
focal
not-affected
jammy
dne
noble
dne
linux-azure-5.19
focal
dne
jammy
ignored
noble
dne
linux-azure-6.2
focal
dne
jammy
ignored
noble
dne
linux-azure-6.5
focal
dne
jammy
ignored
noble
dne
linux-azure-fde
focal
ignored
jammy
not-affected
noble
not-affected
linux-azure-fde-5.15
focal
not-affected
jammy
dne
noble
dne
linux-azure-fde-5.19
focal
dne
jammy
ignored
noble
dne
linux-azure-fde-6.2
focal
dne
jammy
ignored
noble
dne
linux-bluefield
focal
not-affected
jammy
dne
noble
dne
linux-azure-edge
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-fips
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
xenial
not-affected
linux-aws-fips
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
linux-azure-fips
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
linux-gcp-fips
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
dne
linux-gcp
bionic
ignored
focal
not-affected
jammy
not-affected
noble
not-affected
xenial
not-affected
linux-gcp-4.15
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-gcp-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-gcp-5.4
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-gcp-5.8
focal
ignored
jammy
dne
noble
dne
linux-gcp-5.11
focal
ignored
jammy
dne
noble
dne
linux-gcp-5.13
focal
ignored
jammy
dne
noble
dne
linux-gcp-5.15
focal
not-affected
jammy
dne
noble
dne
linux-gcp-5.19
focal
dne
jammy
ignored
noble
dne
linux-gcp-6.2
focal
dne
jammy
ignored
noble
dne
linux-gcp-6.5
focal
dne
jammy
ignored
noble
dne
linux-gke
focal
ignored
jammy
not-affected
noble
not-affected
linux-gke-4.15
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-gke-5.4
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-gke-5.15
focal
ignored
jammy
dne
noble
dne
linux-gkeop-5.4
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-gkeop-5.15
focal
not-affected
jammy
dne
noble
dne
linux-gkeop
focal
not-affected
jammy
not-affected
noble
not-affected
linux-ibm-5.4
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-ibm-5.15
focal
not-affected
jammy
dne
noble
dne
linux-intel-5.13
focal
ignored
jammy
dne
noble
dne
linux-intel-iotg
focal
dne
jammy
not-affected
noble
dne
linux-intel-iotg-5.15
focal
not-affected
jammy
dne
noble
dne
linux-iot
focal
not-affected
jammy
dne
noble
dne
linux-lowlatency
focal
dne
jammy
not-affected
noble
not-affected
linux-lowlatency-hwe-5.15
focal
not-affected
jammy
dne
noble
dne
linux-lowlatency-hwe-5.19
focal
dne
jammy
ignored
noble
dne
linux-lowlatency-hwe-6.2
focal
dne
jammy
ignored
noble
dne
linux-lowlatency-hwe-6.5
focal
dne
jammy
ignored
noble
dne
linux-lowlatency-hwe-6.8
focal
dne
jammy
not-affected
noble
dne
linux-nvidia
focal
dne
jammy
not-affected
noble
not-affected
linux-nvidia-6.2
focal
dne
jammy
ignored
noble
dne
linux-nvidia-6.5
focal
dne
jammy
not-affected
noble
dne
linux-nvidia-6.8
focal
dne
jammy
not-affected
noble
dne
linux-nvidia-lowlatency
focal
dne
jammy
dne
noble
not-affected
linux-oracle-5.0
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-oracle-5.3
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-oracle-5.4
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-oracle-5.8
focal
ignored
jammy
dne
noble
dne
linux-oracle-5.11
focal
ignored
jammy
dne
noble
dne
linux-oracle-5.13
focal
ignored
jammy
dne
noble
dne
linux-oracle-5.15
focal
not-affected
jammy
dne
noble
dne
linux-oracle-6.5
focal
dne
jammy
ignored
noble
dne
linux-oem
bionic
ignored
focal
dne
jammy
dne
noble
dne
linux-oem-5.6
focal
ignored
jammy
dne
noble
dne
linux-oem-5.10
focal
ignored
jammy
dne
noble
dne
linux-oem-5.13
focal
ignored
jammy
dne
noble
dne
linux-oem-5.14
focal
ignored
jammy
dne
noble
dne
linux-oem-5.17
focal
dne
jammy
ignored
noble
dne
linux-oem-6.0
focal
dne
jammy
ignored
noble
dne
linux-oem-6.1
focal
dne
jammy
ignored
noble
dne
linux-oem-6.5
focal
dne
jammy
ignored
noble
dne
linux-oem-6.8
focal
dne
jammy
dne
noble
not-affected
linux-raspi2
focal
ignored
jammy
dne
noble
dne
linux-raspi-5.4
bionic
not-affected
focal
dne
jammy
dne
noble
dne
linux-riscv
focal
ignored
jammy
ignored
noble
not-affected
linux-riscv-5.8
focal
ignored
jammy
dne
noble
dne
linux-riscv-5.11
focal
ignored
jammy
dne
noble
dne
linux-riscv-5.15
focal
not-affected
jammy
dne
noble
dne
linux-riscv-5.19
focal
dne
jammy
ignored
noble
dne
linux-riscv-6.5
focal
dne
jammy
ignored
noble
dne
linux-riscv-6.8
focal
dne
jammy
not-affected
noble
dne
linux-starfive-5.19
focal
dne
jammy
ignored
noble
dne
linux-starfive-6.2
focal
dne
jammy
ignored
noble
dne
linux-starfive-6.5
focal
dne
jammy
ignored
noble
dne
linux-xilinx-zynqmp
focal
not-affected
jammy
not-affected
noble
dne
linux
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
trusty
not-affected
xenial
not-affected
linux-aws
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
trusty
not-affected
xenial
not-affected
linux-ibm
focal
not-affected
jammy
not-affected
noble
not-affected
linux-oracle
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
xenial
not-affected
linux-raspi
focal
not-affected
jammy
not-affected
noble
not-affected
linux-intel
bionic
dne
focal
dne
jammy
dne
noble
not-affected
trusty
dne
xenial
dne
linux-intel-iot-realtime
bionic
dne
focal
dne
jammy
not-affected
noble
dne
trusty
dne
xenial
dne
linux-raspi-realtime
bionic
dne
focal
dne
jammy
dne
noble
not-affected
trusty
dne
xenial
dne
linux-realtime
bionic
dne
focal
dne
jammy
not-affected
noble
not-affected
trusty
dne
xenial
dne