In the Linux kernel, the following vulnerability has been resolved:
net: test for not too small csum_start in virtio_net_hdr_to_skb()
syzbot was able to trigger this warning [1], after injecting a malicious packet through af_packet, setting skb->csum_start and thus the transport header to an incorrect value.
We can at least make sure the transport header is after the end of the network header (with a estimated minimal size).
[1] [ 67.873027] skb len=4096 headroom=16 headlen=14 tailroom=0 mac=(-1,-1) mac_len=0 net=(16,-6) trans=10 shinfo(txflags=0 nr_frags=1 gso(size=0 type=0 segs=0)) csum(0xa start=10 offset=0 ip_summed=3 complete_sw=0 valid=0 level=0) hash(0x0 sw=0 l4=0) proto=0x0800 pkttype=0 iif=0 priority=0x0 mark=0x0 alloc_cpu=10 vlan_all=0x0 encapsulation=0 inner(proto=0x0000, mac=0, net=0, trans=0) [ 67.877172] dev name=veth0_vlan feat=0x000061164fdd09e9 [ 67.877764] sk family=17 type=3 proto=0 [ 67.878279] skb linear: 00000000: 00 00 10 00 00 00 00 00 0f 00 00 00 08 00 [ 67.879128] skb frag: 00000000: 0e 00 07 00 00 00 28 00 08 80 1c 00 04 00 00 02 [ 67.879877] skb frag: 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.880647] skb frag: 00000020: 00 00 02 00 00 00 08 00 1b 00 00 00 00 00 00 00 [ 67.881156] skb frag: 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.881753] skb frag: 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.882173] skb frag: 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.882790] skb frag: 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.883171] skb frag: 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.883733] skb frag: 00000080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.884206] skb frag: 00000090: 00 00 00 00 00 00 00 00 00 00 69 70 76 6c 61 6e [ 67.884704] skb frag: 000000a0: 31 00 00 00 00 00 00 00 00 00 2b 00 00 00 00 00 [ 67.885139] skb frag: 000000b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.885677] skb frag: 000000c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.886042] skb frag: 000000d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.886408] skb frag: 000000e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.887020] skb frag: 000000f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [ 67.887384] skb frag: 00000100: 00 00 [ 67.887878] ------------[ cut here ]------------ [ 67.887908] offset (-6) >= skb_headlen() (14) [ 67.888445] WARNING: CPU: 10 PID: 2088 at net/core/dev.c:3332 skb_checksum_help (net/core/dev.c:3332 (discriminator 2)) [ 67.889353] Modules linked in: macsec macvtap macvlan hsr wireguard curve25519_x86_64 libcurve25519_generic libchacha20poly1305 chacha_x86_64 libchacha poly1305_x86_64 dummy bridge sr_mod cdrom evdev pcspkr i2c_piix4 9pnet_virtio 9p 9pnet netfs [ 67.890111] CPU: 10 UID: 0 PID: 2088 Comm: b363492833 Not tainted 6.11.0-virtme #1011 [ 67.890183] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 67.890309] RIP: 0010:skb_checksum_help (net/core/dev.c:3332 (discriminator 2)) [ 67.891043] Call Trace: [ 67.891173] <TASK> [ 67.891274] ? __warn (kernel/panic.c:741) [ 67.891320] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2)) [ 67.891333] ? report_bug (lib/bug.c:180 lib/bug.c:219) [ 67.891348] ? handle_bug (arch/x86/kernel/traps.c:239) [ 67.891363] ? exc_invalid_op (arch/x86/kernel/traps.c:260 (discriminator 1)) [ 67.891372] ? asm_exc_invalid_op (./arch/x86/include/asm/idtentry.h:621) [ 67.891388] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2)) [ 67.891399] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2)) [ 67.891416] ip_do_fragment (net/ipv4/ip_output.c:777 (discriminator 1)) [ 67.891448] ? __ip_local_out (./include/linux/skbuff.h:1146 ./include/net/l3mdev.h:196 ./include/net/l3mdev.h:213 ne ---truncated---
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-azure-lts-24.04Upgrade linux-image-oem-22.04aUpgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-azure-fdeUpgrade linux-image-6.8.0-54-lowlatency-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-gcp-lts-24.04Upgrade linux-image-6.8.0-1019-gkeUpgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-oracle-64k-lts-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-6.11.0-1009-azureUpgrade linux-image-6.8.0-1024-gcp-64kUpgrade linux-image-aws-lts-24.04Upgrade linux-image-virtual-hwe-22.04Upgrade linux-image-oem-24.04aUpgrade linux-image-6.8.0-1022-nvidia-lowlatency-64kUpgrade linux-image-gcpUpgrade linux-image-6.8.0-1020-oracleUpgrade linux-image-awsUpgrade linux-image-6.8.0-1024-gcpUpgrade linux-image-6.8.0-54-lowlatencyUpgrade linux-image-6.8.0-57-generic-64kUpgrade linux-image-oem-22.04bUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.8.0-54-generic-64kUpgrade linux-image-6.8.0-1022-ibmUpgrade linux-image-kvmUpgrade linux-image-6.8.0-1019-raspiUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-ibmUpgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-oracleUpgrade linux-image-azure-fde-lts-24.04Upgrade linux-image-generic-hwe-22.04Upgrade linux-image-6.8.0-1022-nvidia-64kUpgrade linux-image-6.8.0-54-genericUpgrade linux-image-ibm-classicUpgrade linux-image-virtualUpgrade linux-image-6.11.0-1015-oemUpgrade linux-image-nvidia-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-gkeop-6.8Upgrade linux-image-6.8.0-1006-gkeopUpgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-oem-22.04dUpgrade linux-image-6.8.0-1022-nvidiaUpgrade linux-image-gkeopUpgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-lowlatencyUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-oem-24.04bUpgrade linux-image-gcp-64kUpgrade linux-image-oem-22.04Upgrade linux-image-6.8.0-1020-oracle-64kUpgrade linux-image-nvidia-6.8Upgrade linux-image-azureUpgrade linux-image-6.11.0-18-genericUpgrade linux-image-nvidiaUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-6.8.0-1025-azureUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-oem-22.04cUpgrade linux-image-6.8.0-1023-awsUpgrade linux-image-6.8.0-57-genericUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-6.8.0-1024-oemUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-generic-64kUpgrade linux-image-oem-24.04Upgrade linux-image-6.8.0-1025-azure-fdeUpgrade linux-image-generic-lpaeUpgrade linux-image-raspiUpgrade linux-image-oracle-lts-24.04Upgrade linux-image-gkeUpgrade linux-image-6.8.0-1022-nvidia-lowlatencyUpgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-genericUpgrade linux-image-lowlatency-64kUpgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-6.11.0-1009-awsUpgrade linux-image-realtimeUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-realtime-hwe-24.04 | Feb 20, 2025 | Oct 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub