CVE-2024-27026

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/05/2024
Last modified:
05/03/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> vmxnet3: Fix missing reserved tailroom<br /> <br /> Use rbi-&gt;len instead of rcd-&gt;len for non-dataring packet.<br /> <br /> Found issue:<br /> XDP_WARN: xdp_update_frame_from_buff(line:278): Driver BUG: missing reserved tailroom<br /> WARNING: CPU: 0 PID: 0 at net/core/xdp.c:586 xdp_warn+0xf/0x20<br /> CPU: 0 PID: 0 Comm: swapper/0 Tainted: G W O 6.5.1 #1<br /> RIP: 0010:xdp_warn+0xf/0x20<br /> ...<br /> ? xdp_warn+0xf/0x20<br /> xdp_do_redirect+0x15f/0x1c0<br /> vmxnet3_run_xdp+0x17a/0x400 [vmxnet3]<br /> vmxnet3_process_xdp+0xe4/0x760 [vmxnet3]<br /> ? vmxnet3_tq_tx_complete.isra.0+0x21e/0x2c0 [vmxnet3]<br /> vmxnet3_rq_rx_complete+0x7ad/0x1120 [vmxnet3]<br /> vmxnet3_poll_rx_only+0x2d/0xa0 [vmxnet3]<br /> __napi_poll+0x20/0x180<br /> net_rx_action+0x177/0x390

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6 (including) 6.6.23 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.11 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.8 (including) 6.8.2 (excluding)