← CVE Tracker
9.8CRITICAL
CVE-2024-49568 — In the Linux kernel, the following vulnerability has been resolved: net/smc: check…
Linux · Linux Kernel · Published 11 Jan 2025 · Modified 3 Oct 2026
Description
In the Linux kernel, the following vulnerability has been resolved: net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg When receiving proposal msg in server, the fields v2_ext_offset/ eid_cnt/ism_gid_cnt in proposal msg are from the remote client and can not be fully trusted. Especially the field v2_ext_offset, once exceed the max value, there has the chance to access wrong address, and crash may happen. This patch checks the fields v2_ext_offset/eid_cnt/ism_gid_cnt before using them.
References
- https://git.kernel.org/stable/c/295a92e3df32e72aff0f4bc25c310e349d07ffbf
- https://git.kernel.org/stable/c/42f6beb2d5779429417b5f8115a4e3fa695d2a6c
- https://git.kernel.org/stable/c/49798283fce4c1a24fb1ba4c7c39127739535571
- https://git.kernel.org/stable/c/690b9a8db9460d065785548e43fd6a02d247c1b7
- https://git.kernel.org/stable/c/7863c9f3d24ba49dbead7e03dfbe40deb5888fdf
- https://git.kernel.org/stable/c/9cc0170ae646876aa5de2f0cad3066ce53e86f27
What to do
- Check whether Linux Kernel is in your asset inventory.
- Patch in the next maintenance window; prioritise internet-facing systems.
- Record the decision in your risk register for audit evidence.
Share
Link: adminadda.com/cve/CVE-2024-49568