CVE-2024-50258

Source
https://cve.org/CVERecord?id=CVE-2024-50258
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-50258.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-50258
Downstream
Related
Published
2024-11-09T10:15:11Z
Modified
2026-08-12T03:51:37Z
Summary
net: fix crash when config small gso_max_size/gso_ipv4_max_size
Details

In the Linux kernel, the following vulnerability has been resolved:

net: fix crash when config small gso_max_size/gso_ipv4_max_size

Config a small gso_max_size/gso_ipv4_max_size will lead to an underflow in sk_dst_gso_max_size(), which may trigger a BUG_ON crash, because sk->sk_gso_max_size would be much bigger than device limits. Call Trace: tcp_write_xmit tso_segs = tcp_init_tso_segs(skb, mss_now); tcp_set_skb_tso_segs tcp_skb_pcount_set // skb->len = 524288, mss_now = 8 // u16 tso_segs = 524288/8 = 65535 -> 0 tso_segs = DIV_ROUND_UP(skb->len, mss_now) BUG_ON(!tso_segs) Add check for the minimum value of gso_max_size and gso_ipv4_max_size.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50258.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
46e6b992c2502b094e61da6994f1363f3b7c1413
Fixed
90c8482a5d9791259ba77bfdc1849fc5128b4be7
Fixed
e9365368b483328639c03fc730448dccd5a25b6b
Fixed
ac5977001eee7660c643f8e07a2de9001990b7b8
Fixed
e72fd1389a5364bc6aa6312ecf30bdb5891b9486
Fixed
9ab5cf19fb0e4680f95e506d6c544259bf1111c4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-50258.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.15.181
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.120
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.60
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.11.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-50258.json"