CVE-2024-50045 (GCVE-0-2024-50045)
Vulnerability from cvelistv5
Published
2024-10-21 19:39
Modified
2026-08-05 11:41
Summary
In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: fix panic with metadata_dst skb Fix a kernel panic in the br_netfilter module when sending untagged traffic via a VxLAN device. This happens during the check for fragmentation in br_nf_dev_queue_xmit. It is dependent on: 1) the br_netfilter module being loaded; 2) net.bridge.bridge-nf-call-iptables set to 1; 3) a bridge with a VxLAN (single-vxlan-device) netdevice as a bridge port; 4) untagged frames with size higher than the VxLAN MTU forwarded/flooded When forwarding the untagged packet to the VxLAN bridge port, before the netfilter hooks are called, br_handle_egress_vlan_tunnel is called and changes the skb_dst to the tunnel dst. The tunnel_dst is a metadata type of dst, i.e., skb_valid_dst(skb) is false, and metadata->dst.dev is NULL. Then in the br_netfilter hooks, in br_nf_dev_queue_xmit, there's a check for frames that needs to be fragmented: frames with higher MTU than the VxLAN device end up calling br_nf_ip_fragment, which in turns call ip_skb_dst_mtu. The ip_dst_mtu tries to use the skb_dst(skb) as if it was a valid dst with valid dst->dev, thus the crash. This case was never supported in the first place, so drop the packet instead. PING 10.0.0.2 (10.0.0.2) from 0.0.0.0 h1-eth0: 2000(2028) bytes of data. [ 176.291791] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000110 [ 176.292101] Mem abort info: [ 176.292184] ESR = 0x0000000096000004 [ 176.292322] EC = 0x25: DABT (current EL), IL = 32 bits [ 176.292530] SET = 0, FnV = 0 [ 176.292709] EA = 0, S1PTW = 0 [ 176.292862] FSC = 0x04: level 0 translation fault [ 176.293013] Data abort info: [ 176.293104] ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 [ 176.293488] CM = 0, WnR = 0, TnD = 0, TagAccess = 0 [ 176.293787] GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [ 176.293995] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000043ef5000 [ 176.294166] [0000000000000110] pgd=0000000000000000, p4d=0000000000000000 [ 176.294827] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP [ 176.295252] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel veth br_netfilter bridge stp llc ipv6 crct10dif_ce [ 176.295923] CPU: 0 PID: 188 Comm: ping Not tainted 6.8.0-rc3-g5b3fbd61b9d1 #2 [ 176.296314] Hardware name: linux,dummy-virt (DT) [ 176.296535] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 176.296808] pc : br_nf_dev_queue_xmit+0x390/0x4ec [br_netfilter] [ 176.297382] lr : br_nf_dev_queue_xmit+0x2ac/0x4ec [br_netfilter] [ 176.297636] sp : ffff800080003630 [ 176.297743] x29: ffff800080003630 x28: 0000000000000008 x27: ffff6828c49ad9f8 [ 176.298093] x26: ffff6828c49ad000 x25: 0000000000000000 x24: 00000000000003e8 [ 176.298430] x23: 0000000000000000 x22: ffff6828c4960b40 x21: ffff6828c3b16d28 [ 176.298652] x20: ffff6828c3167048 x19: ffff6828c3b16d00 x18: 0000000000000014 [ 176.298926] x17: ffffb0476322f000 x16: ffffb7e164023730 x15: 0000000095744632 [ 176.299296] x14: ffff6828c3f1c880 x13: 0000000000000002 x12: ffffb7e137926a70 [ 176.299574] x11: 0000000000000001 x10: ffff6828c3f1c898 x9 : 0000000000000000 [ 176.300049] x8 : ffff6828c49bf070 x7 : 0008460f18d5f20e x6 : f20e0100bebafeca [ 176.300302] x5 : ffff6828c7f918fe x4 : ffff6828c49bf070 x3 : 0000000000000000 [ 176.300586] x2 : 0000000000000000 x1 : ffff6828c3c7ad00 x0 : ffff6828c7f918f0 [ 176.300889] Call trace: [ 176.301123] br_nf_dev_queue_xmit+0x390/0x4ec [br_netfilter] [ 176.301411] br_nf_post_routing+0x2a8/0x3e4 [br_netfilter] [ 176.301703] nf_hook_slow+0x48/0x124 [ 176.302060] br_forward_finish+0xc8/0xe8 [bridge] [ 176.302371] br_nf_hook_thresh+0x124/0x134 [br_netfilter] [ 176.302605] br_nf_forward_finish+0x118/0x22c [br_netfilter] [ 176.302824] br_nf_forward_ip.part.0+0x264/0x290 [br_netfilter] [ 176.303136] br_nf_forward+0x2b8/0x4e0 [br_netfilter] [ 176.303359] nf_hook_slow+0x48/0x124 [ 176.303 ---truncated---
Impacted products
Vendor Product Version
Linux Linux Version: 11538d039ac6efcf4f1a6c536e1b87cd3668a9fd
Version: 11538d039ac6efcf4f1a6c536e1b87cd3668a9fd
Version: 11538d039ac6efcf4f1a6c536e1b87cd3668a9fd
Version: 11538d039ac6efcf4f1a6c536e1b87cd3668a9fd
Version: 11538d039ac6efcf4f1a6c536e1b87cd3668a9fd
Version: 11538d039ac6efcf4f1a6c536e1b87cd3668a9fd
Version: 11538d039ac6efcf4f1a6c536e1b87cd3668a9fd
Version: 11538d039ac6efcf4f1a6c536e1b87cd3668a9fd
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-50045",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2024-10-22T13:24:15.720711Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2024-10-22T13:28:43.698Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      },
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T22:24:51.294Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "RUGGEDCOM RST2428P",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V3.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V3.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SCALANCE XCM-/XRM-/XCH-/XRH-300 family",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V3.2",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V3.1.5",
                "status": "affected",
                "version": "V3.1.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V3.1.5",
                "status": "affected",
                "version": "V3.1.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V3.1.5",
                "status": "affected",
                "version": "V3.1.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V3.1.5",
                "status": "affected",
                "version": "V3.1.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V3.1.5",
                "status": "affected",
                "version": "V3.1.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-05-12T12:00:09.406Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-398330.html"
          },
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
          },
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-355557.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/bridge/br_netfilter_hooks.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "f07131239a76cc10d5e82c19d91f53cb55727297",
              "status": "affected",
              "version": "11538d039ac6efcf4f1a6c536e1b87cd3668a9fd",
              "versionType": "git"
            },
            {
              "lessThan": "75dfcb758015c97e1accd6340691fca67d363bed",
              "status": "affected",
              "version": "11538d039ac6efcf4f1a6c536e1b87cd3668a9fd",
              "versionType": "git"
            },
            {
              "lessThan": "cce8419b8168f6e7eb637103a47f916f3de8bc81",
              "status": "affected",
              "version": "11538d039ac6efcf4f1a6c536e1b87cd3668a9fd",
              "versionType": "git"
            },
            {
              "lessThan": "95c0cff5a1a5d28bf623b92eb5d1a8f56ed30803",
              "status": "affected",
              "version": "11538d039ac6efcf4f1a6c536e1b87cd3668a9fd",
              "versionType": "git"
            },
            {
              "lessThan": "78ed917133b118661e1fe62d4a85d5d428ee9568",
              "status": "affected",
              "version": "11538d039ac6efcf4f1a6c536e1b87cd3668a9fd",
              "versionType": "git"
            },
            {
              "lessThan": "3453f5839420bfbb85c86c61e49f49ffd0f041c4",
              "status": "affected",
              "version": "11538d039ac6efcf4f1a6c536e1b87cd3668a9fd",
              "versionType": "git"
            },
            {
              "lessThan": "915717e0bb9837cc5c101bc545af487bd787239e",
              "status": "affected",
              "version": "11538d039ac6efcf4f1a6c536e1b87cd3668a9fd",
              "versionType": "git"
            },
            {
              "lessThan": "f9ff7665cd128012868098bbd07e28993e314fdb",
              "status": "affected",
              "version": "11538d039ac6efcf4f1a6c536e1b87cd3668a9fd",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/bridge/br_netfilter_hooks.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.11"
            },
            {
              "lessThan": "4.11",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "4.19.*",
              "status": "unaffected",
              "version": "4.19.323",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.285",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.227",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.168",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.113",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.57",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.11.*",
              "status": "unaffected",
              "version": "6.11.4",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.12",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "4.19.323",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.285",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.227",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.168",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.113",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.57",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.11.4",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12",
                  "versionStartIncluding": "4.11",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: br_netfilter: fix panic with metadata_dst skb\n\nFix a kernel panic in the br_netfilter module when sending untagged\ntraffic via a VxLAN device.\nThis happens during the check for fragmentation in br_nf_dev_queue_xmit.\n\nIt is dependent on:\n1) the br_netfilter module being loaded;\n2) net.bridge.bridge-nf-call-iptables set to 1;\n3) a bridge with a VxLAN (single-vxlan-device) netdevice as a bridge port;\n4) untagged frames with size higher than the VxLAN MTU forwarded/flooded\n\nWhen forwarding the untagged packet to the VxLAN bridge port, before\nthe netfilter hooks are called, br_handle_egress_vlan_tunnel is called and\nchanges the skb_dst to the tunnel dst. The tunnel_dst is a metadata type\nof dst, i.e., skb_valid_dst(skb) is false, and metadata-\u003edst.dev is NULL.\n\nThen in the br_netfilter hooks, in br_nf_dev_queue_xmit, there\u0027s a check\nfor frames that needs to be fragmented: frames with higher MTU than the\nVxLAN device end up calling br_nf_ip_fragment, which in turns call\nip_skb_dst_mtu.\n\nThe ip_dst_mtu tries to use the skb_dst(skb) as if it was a valid dst\nwith valid dst-\u003edev, thus the crash.\n\nThis case was never supported in the first place, so drop the packet\ninstead.\n\nPING 10.0.0.2 (10.0.0.2) from 0.0.0.0 h1-eth0: 2000(2028) bytes of data.\n[  176.291791] Unable to handle kernel NULL pointer dereference at\nvirtual address 0000000000000110\n[  176.292101] Mem abort info:\n[  176.292184]   ESR = 0x0000000096000004\n[  176.292322]   EC = 0x25: DABT (current EL), IL = 32 bits\n[  176.292530]   SET = 0, FnV = 0\n[  176.292709]   EA = 0, S1PTW = 0\n[  176.292862]   FSC = 0x04: level 0 translation fault\n[  176.293013] Data abort info:\n[  176.293104]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n[  176.293488]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n[  176.293787]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n[  176.293995] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000043ef5000\n[  176.294166] [0000000000000110] pgd=0000000000000000,\np4d=0000000000000000\n[  176.294827] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[  176.295252] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel veth\nbr_netfilter bridge stp llc ipv6 crct10dif_ce\n[  176.295923] CPU: 0 PID: 188 Comm: ping Not tainted\n6.8.0-rc3-g5b3fbd61b9d1 #2\n[  176.296314] Hardware name: linux,dummy-virt (DT)\n[  176.296535] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS\nBTYPE=--)\n[  176.296808] pc : br_nf_dev_queue_xmit+0x390/0x4ec [br_netfilter]\n[  176.297382] lr : br_nf_dev_queue_xmit+0x2ac/0x4ec [br_netfilter]\n[  176.297636] sp : ffff800080003630\n[  176.297743] x29: ffff800080003630 x28: 0000000000000008 x27:\nffff6828c49ad9f8\n[  176.298093] x26: ffff6828c49ad000 x25: 0000000000000000 x24:\n00000000000003e8\n[  176.298430] x23: 0000000000000000 x22: ffff6828c4960b40 x21:\nffff6828c3b16d28\n[  176.298652] x20: ffff6828c3167048 x19: ffff6828c3b16d00 x18:\n0000000000000014\n[  176.298926] x17: ffffb0476322f000 x16: ffffb7e164023730 x15:\n0000000095744632\n[  176.299296] x14: ffff6828c3f1c880 x13: 0000000000000002 x12:\nffffb7e137926a70\n[  176.299574] x11: 0000000000000001 x10: ffff6828c3f1c898 x9 :\n0000000000000000\n[  176.300049] x8 : ffff6828c49bf070 x7 : 0008460f18d5f20e x6 :\nf20e0100bebafeca\n[  176.300302] x5 : ffff6828c7f918fe x4 : ffff6828c49bf070 x3 :\n0000000000000000\n[  176.300586] x2 : 0000000000000000 x1 : ffff6828c3c7ad00 x0 :\nffff6828c7f918f0\n[  176.300889] Call trace:\n[  176.301123]  br_nf_dev_queue_xmit+0x390/0x4ec [br_netfilter]\n[  176.301411]  br_nf_post_routing+0x2a8/0x3e4 [br_netfilter]\n[  176.301703]  nf_hook_slow+0x48/0x124\n[  176.302060]  br_forward_finish+0xc8/0xe8 [bridge]\n[  176.302371]  br_nf_hook_thresh+0x124/0x134 [br_netfilter]\n[  176.302605]  br_nf_forward_finish+0x118/0x22c [br_netfilter]\n[  176.302824]  br_nf_forward_ip.part.0+0x264/0x290 [br_netfilter]\n[  176.303136]  br_nf_forward+0x2b8/0x4e0 [br_netfilter]\n[  176.303359]  nf_hook_slow+0x48/0x124\n[  176.303\n---truncated---"
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The crash is driven entirely by an inbound/forwarded packet processed by the bridge netfilter data path on a VXLAN VTEP; the upstream regression test triggers the panic with a single ping originated on a different machine, and in an EVPN gateway any routed full-MTU packet destined to an overlay MAC reachable via the VXLAN port takes the same fragmentation path from an arbitrary L3 source.\nAC:L - No race, no memory-layout dependency and no timing window \u2014 the attacker only has to send one IP packet larger than the VXLAN port\u0027s MTU, which is the normal case since the VXLAN device MTU is ~50 bytes below the bridge\u0027s, and `bridge-nf-call-iptables` defaults to 1 whenever br_netfilter is loaded.\nPR:N - The packet is handled in `br_handle_frame`/`br_flood`/`br_nf_post_routing` before any authentication or authorization; the attacker needs no account, capability or credential on the VTEP, only the ability to emit a packet that the bridge forwards to the VXLAN port.\nUI:N - Processing happens automatically in NAPI/softirq context as soon as the frame is forwarded; no administrator or local user has to do anything beyond the VXLAN bridge already being configured.\nS:U - The NULL dereference faults inside the host kernel\u0027s bridge/netfilter forwarding path, and the damage is confined to that same kernel \u2014 no VM, IOMMU or sandbox boundary is crossed.\nC:N - `dev_net(dst-\u003edev)` dereferences a NULL `dst-\u003edev` at the fixed offset 0x110 and faults immediately; no attacker-influenced or out-of-bounds memory is read back or disclosed.\nI:N - Execution aborts at the faulting read before any store \u2014 there is no out-of-bounds or use-after-free write, and `mmap_min_addr` prevents mapping the NULL page to convert the dereference into a write primitive.\nA:H - The oops occurs in softirq/NAPI context, which is a fatal exception in interrupt and takes the whole machine down with \"Kernel panic - not syncing\"; an unauthenticated attacker can repeat it with a single oversized packet to permanently deny service on the VTEP."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:41:14.018Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/f07131239a76cc10d5e82c19d91f53cb55727297"
        },
        {
          "url": "https://git.kernel.org/stable/c/75dfcb758015c97e1accd6340691fca67d363bed"
        },
        {
          "url": "https://git.kernel.org/stable/c/cce8419b8168f6e7eb637103a47f916f3de8bc81"
        },
        {
          "url": "https://git.kernel.org/stable/c/95c0cff5a1a5d28bf623b92eb5d1a8f56ed30803"
        },
        {
          "url": "https://git.kernel.org/stable/c/78ed917133b118661e1fe62d4a85d5d428ee9568"
        },
        {
          "url": "https://git.kernel.org/stable/c/3453f5839420bfbb85c86c61e49f49ffd0f041c4"
        },
        {
          "url": "https://git.kernel.org/stable/c/915717e0bb9837cc5c101bc545af487bd787239e"
        },
        {
          "url": "https://git.kernel.org/stable/c/f9ff7665cd128012868098bbd07e28993e314fdb"
        }
      ],
      "title": "netfilter: br_netfilter: fix panic with metadata_dst skb",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-50045",
    "datePublished": "2024-10-21T19:39:43.117Z",
    "dateReserved": "2024-10-21T12:17:06.071Z",
    "dateUpdated": "2026-08-05T11:41:14.018Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "vulnrichment": {
      "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html\"}, {\"url\": \"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html\"}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2025-11-03T22:24:51.294Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2024-50045\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2024-10-22T13:24:15.720711Z\"}}}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2024-10-22T13:24:18.789Z\"}}], \"cna\": {\"title\": \"netfilter: br_netfilter: fix panic with metadata_dst skb\", \"affected\": [{\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"11538d039ac6efcf4f1a6c536e1b87cd3668a9fd\", \"lessThan\": \"f07131239a76cc10d5e82c19d91f53cb55727297\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"11538d039ac6efcf4f1a6c536e1b87cd3668a9fd\", \"lessThan\": \"75dfcb758015c97e1accd6340691fca67d363bed\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"11538d039ac6efcf4f1a6c536e1b87cd3668a9fd\", \"lessThan\": \"cce8419b8168f6e7eb637103a47f916f3de8bc81\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"11538d039ac6efcf4f1a6c536e1b87cd3668a9fd\", \"lessThan\": \"95c0cff5a1a5d28bf623b92eb5d1a8f56ed30803\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"11538d039ac6efcf4f1a6c536e1b87cd3668a9fd\", \"lessThan\": \"78ed917133b118661e1fe62d4a85d5d428ee9568\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"11538d039ac6efcf4f1a6c536e1b87cd3668a9fd\", \"lessThan\": \"3453f5839420bfbb85c86c61e49f49ffd0f041c4\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"11538d039ac6efcf4f1a6c536e1b87cd3668a9fd\", \"lessThan\": \"915717e0bb9837cc5c101bc545af487bd787239e\", \"versionType\": \"git\"}, {\"status\": \"affected\", \"version\": \"11538d039ac6efcf4f1a6c536e1b87cd3668a9fd\", \"lessThan\": \"f9ff7665cd128012868098bbd07e28993e314fdb\", \"versionType\": \"git\"}], \"programFiles\": [\"net/bridge/br_netfilter_hooks.c\"], \"defaultStatus\": \"unaffected\"}, {\"repo\": \"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git\", \"vendor\": \"Linux\", \"product\": \"Linux\", \"versions\": [{\"status\": \"affected\", \"version\": \"4.11\"}, {\"status\": \"unaffected\", \"version\": \"0\", \"lessThan\": \"4.11\", \"versionType\": \"semver\"}, {\"status\": \"unaffected\", \"version\": \"4.19.323\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"4.19.*\"}, {\"status\": \"unaffected\", \"version\": \"5.4.285\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.4.*\"}, {\"status\": \"unaffected\", \"version\": \"5.10.227\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.10.*\"}, {\"status\": \"unaffected\", \"version\": \"5.15.168\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"5.15.*\"}, {\"status\": \"unaffected\", \"version\": \"6.1.113\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.1.*\"}, {\"status\": \"unaffected\", \"version\": \"6.6.57\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.6.*\"}, {\"status\": \"unaffected\", \"version\": \"6.11.4\", \"versionType\": \"semver\", \"lessThanOrEqual\": \"6.11.*\"}, {\"status\": \"unaffected\", \"version\": \"6.12\", \"versionType\": \"original_commit_for_fix\", \"lessThanOrEqual\": \"*\"}], \"programFiles\": [\"net/bridge/br_netfilter_hooks.c\"], \"defaultStatus\": \"affected\"}], \"references\": [{\"url\": \"https://git.kernel.org/stable/c/f07131239a76cc10d5e82c19d91f53cb55727297\"}, {\"url\": \"https://git.kernel.org/stable/c/75dfcb758015c97e1accd6340691fca67d363bed\"}, {\"url\": \"https://git.kernel.org/stable/c/cce8419b8168f6e7eb637103a47f916f3de8bc81\"}, {\"url\": \"https://git.kernel.org/stable/c/95c0cff5a1a5d28bf623b92eb5d1a8f56ed30803\"}, {\"url\": \"https://git.kernel.org/stable/c/78ed917133b118661e1fe62d4a85d5d428ee9568\"}, {\"url\": \"https://git.kernel.org/stable/c/3453f5839420bfbb85c86c61e49f49ffd0f041c4\"}, {\"url\": \"https://git.kernel.org/stable/c/915717e0bb9837cc5c101bc545af487bd787239e\"}, {\"url\": \"https://git.kernel.org/stable/c/f9ff7665cd128012868098bbd07e28993e314fdb\"}], \"x_generator\": {\"engine\": \"bippy-1.2.0\"}, \"descriptions\": [{\"lang\": \"en\", \"value\": \"In the Linux kernel, the following vulnerability has been resolved:\\n\\nnetfilter: br_netfilter: fix panic with metadata_dst skb\\n\\nFix a kernel panic in the br_netfilter module when sending untagged\\ntraffic via a VxLAN device.\\nThis happens during the check for fragmentation in br_nf_dev_queue_xmit.\\n\\nIt is dependent on:\\n1) the br_netfilter module being loaded;\\n2) net.bridge.bridge-nf-call-iptables set to 1;\\n3) a bridge with a VxLAN (single-vxlan-device) netdevice as a bridge port;\\n4) untagged frames with size higher than the VxLAN MTU forwarded/flooded\\n\\nWhen forwarding the untagged packet to the VxLAN bridge port, before\\nthe netfilter hooks are called, br_handle_egress_vlan_tunnel is called and\\nchanges the skb_dst to the tunnel dst. The tunnel_dst is a metadata type\\nof dst, i.e., skb_valid_dst(skb) is false, and metadata-\u003edst.dev is NULL.\\n\\nThen in the br_netfilter hooks, in br_nf_dev_queue_xmit, there\u0027s a check\\nfor frames that needs to be fragmented: frames with higher MTU than the\\nVxLAN device end up calling br_nf_ip_fragment, which in turns call\\nip_skb_dst_mtu.\\n\\nThe ip_dst_mtu tries to use the skb_dst(skb) as if it was a valid dst\\nwith valid dst-\u003edev, thus the crash.\\n\\nThis case was never supported in the first place, so drop the packet\\ninstead.\\n\\nPING 10.0.0.2 (10.0.0.2) from 0.0.0.0 h1-eth0: 2000(2028) bytes of data.\\n[  176.291791] Unable to handle kernel NULL pointer dereference at\\nvirtual address 0000000000000110\\n[  176.292101] Mem abort info:\\n[  176.292184]   ESR = 0x0000000096000004\\n[  176.292322]   EC = 0x25: DABT (current EL), IL = 32 bits\\n[  176.292530]   SET = 0, FnV = 0\\n[  176.292709]   EA = 0, S1PTW = 0\\n[  176.292862]   FSC = 0x04: level 0 translation fault\\n[  176.293013] Data abort info:\\n[  176.293104]   ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\\n[  176.293488]   CM = 0, WnR = 0, TnD = 0, TagAccess = 0\\n[  176.293787]   GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\\n[  176.293995] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000043ef5000\\n[  176.294166] [0000000000000110] pgd=0000000000000000,\\np4d=0000000000000000\\n[  176.294827] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\\n[  176.295252] Modules linked in: vxlan ip6_udp_tunnel udp_tunnel veth\\nbr_netfilter bridge stp llc ipv6 crct10dif_ce\\n[  176.295923] CPU: 0 PID: 188 Comm: ping Not tainted\\n6.8.0-rc3-g5b3fbd61b9d1 #2\\n[  176.296314] Hardware name: linux,dummy-virt (DT)\\n[  176.296535] pstate: 80000005 (Nzcv daif -PAN -UAO -TCO -DIT -SSBS\\nBTYPE=--)\\n[  176.296808] pc : br_nf_dev_queue_xmit+0x390/0x4ec [br_netfilter]\\n[  176.297382] lr : br_nf_dev_queue_xmit+0x2ac/0x4ec [br_netfilter]\\n[  176.297636] sp : ffff800080003630\\n[  176.297743] x29: ffff800080003630 x28: 0000000000000008 x27:\\nffff6828c49ad9f8\\n[  176.298093] x26: ffff6828c49ad000 x25: 0000000000000000 x24:\\n00000000000003e8\\n[  176.298430] x23: 0000000000000000 x22: ffff6828c4960b40 x21:\\nffff6828c3b16d28\\n[  176.298652] x20: ffff6828c3167048 x19: ffff6828c3b16d00 x18:\\n0000000000000014\\n[  176.298926] x17: ffffb0476322f000 x16: ffffb7e164023730 x15:\\n0000000095744632\\n[  176.299296] x14: ffff6828c3f1c880 x13: 0000000000000002 x12:\\nffffb7e137926a70\\n[  176.299574] x11: 0000000000000001 x10: ffff6828c3f1c898 x9 :\\n0000000000000000\\n[  176.300049] x8 : ffff6828c49bf070 x7 : 0008460f18d5f20e x6 :\\nf20e0100bebafeca\\n[  176.300302] x5 : ffff6828c7f918fe x4 : ffff6828c49bf070 x3 :\\n0000000000000000\\n[  176.300586] x2 : 0000000000000000 x1 : ffff6828c3c7ad00 x0 :\\nffff6828c7f918f0\\n[  176.300889] Call trace:\\n[  176.301123]  br_nf_dev_queue_xmit+0x390/0x4ec [br_netfilter]\\n[  176.301411]  br_nf_post_routing+0x2a8/0x3e4 [br_netfilter]\\n[  176.301703]  nf_hook_slow+0x48/0x124\\n[  176.302060]  br_forward_finish+0xc8/0xe8 [bridge]\\n[  176.302371]  br_nf_hook_thresh+0x124/0x134 [br_netfilter]\\n[  176.302605]  br_nf_forward_finish+0x118/0x22c [br_netfilter]\\n[  176.302824]  br_nf_forward_ip.part.0+0x264/0x290 [br_netfilter]\\n[  176.303136]  br_nf_forward+0x2b8/0x4e0 [br_netfilter]\\n[  176.303359]  nf_hook_slow+0x48/0x124\\n[  176.303\\n---truncated---\"}], \"cpeApplicability\": [{\"nodes\": [{\"negate\": false, \"cpeMatch\": [{\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"4.19.323\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.4.285\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.10.227\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"5.15.168\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.1.113\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.6.57\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.11.4\", \"versionStartIncluding\": \"4.11\"}, {\"criteria\": \"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*\", \"vulnerable\": true, \"versionEndExcluding\": \"6.12\", \"versionStartIncluding\": \"4.11\"}], \"operator\": \"OR\"}]}], \"providerMetadata\": {\"orgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"shortName\": \"Linux\", \"dateUpdated\": \"2026-05-11T20:44:25.711Z\"}}}",
      "cveMetadata": "{\"cveId\": \"CVE-2024-50045\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2026-05-11T20:44:25.711Z\", \"dateReserved\": \"2024-10-21T12:17:06.071Z\", \"assignerOrgId\": \"416baaa9-dc9f-4396-8d5f-8c081fb06d67\", \"datePublished\": \"2024-10-21T19:39:43.117Z\", \"assignerShortName\": \"Linux\"}",
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…