In the Linux kernel, the following vulnerability has been resolved:
tcp: add sanity tests to TCP_QUEUE_SEQ
Qingyu Li reported a syzkaller bug where the repro changes RCV SEQ _after_ restoring data in the receive queue.
mprotect(0x4aa000, 12288, PROT_READ) = 0 mmap(0x1ffff000, 4096, PROT_NONE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x1ffff000 mmap(0x20000000, 16777216, PROT_READ|PROT_WRITE|PROT_EXEC, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x20000000 mmap(0x21000000, 4096, PROT_NONE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x21000000 socket(AF_INET6, SOCK_STREAM, IPPROTO_IP) = 3 setsockopt(3, SOL_TCP, TCP_REPAIR, [1], 4) = 0 connect(3, {sa_family=AF_INET6, sin6_port=htons(0), sin6_flowinfo=htonl(0), inet_pton(AF_INET6, "::1", &sin6_addr), sin6_scope_id=0}, 28) = 0 setsockopt(3, SOL_TCP, TCP_REPAIR_QUEUE, [1], 4) = 0 sendmsg(3, {msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="0x0000000000000003\0\0", iov_len=20}], msg_iovlen=1, msg_controllen=0, msg_flags=0}, 0) = 20 setsockopt(3, SOL_TCP, TCP_REPAIR, [0], 4) = 0 setsockopt(3, SOL_TCP, TCP_QUEUE_SEQ, [128], 4) = 0 recvfrom(3, NULL, 20, 0, NULL, NULL) = -1 ECONNRESET (Connection reset by peer)
syslog shows: [ 111.205099] TCP recvmsg seq # bug 2: copied 80, seq 0, rcvnxt 80, fl 0 [ 111.207894] WARNING: CPU: 1 PID: 356 at net/ipv4/tcp.c:2343 tcp_recvmsg_locked+0x90e/0x29a0
This should not be allowed. TCP_QUEUE_SEQ should only be used when queues are empty.
This patch fixes this case, and the tx path as well.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade kernel-debuginfoUpgrade python-perfUpgrade kernelUpgrade kernel-toolsUpgrade kernel-tools-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade bpftoolUpgrade perf-debuginfoUpgrade kernel-headersUpgrade kernel-debuginfo-common-aarch64Upgrade python-perf-debuginfoUpgrade kernel-develUpgrade kernel-tools-develUpgrade perf | Sep 16, 2024 | Aug 29, 2024 |
| Debian | — | Upgrade linux | Sep 2, 2024 | Aug 29, 2024 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 29, 2024 |
| Ubuntu | — | Upgrade linux-raspi-5.4Upgrade linux-aws-5.4Upgrade linux-oracle-5.4Upgrade linux-azureUpgrade linux-gcpUpgrade linux-awsUpgrade linux-azure-4.15Upgrade linux-raspiUpgrade linux-hweUpgrade linux-hwe-5.4Upgrade linux-kvmUpgrade linuxUpgrade linux-azure-fipsUpgrade linux-oracleUpgrade linux-gkeopUpgrade linux-aws-hweUpgrade linux-gcp-5.4Upgrade linux-aws-fipsUpgrade linux-gcp-fipsUpgrade linux-gcp-4.15Upgrade linux-azure-5.4Upgrade linux-fips | Nov 19, 2024 | Aug 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub