CVE-2024-57791 (GCVE-0-2024-57791)
Vulnerability from cvelistv5
Published
2025-01-11 12:35
Modified
2026-08-05 11:46
Summary
In the Linux kernel, the following vulnerability has been resolved: net/smc: check return value of sock_recvmsg when draining clc data When receiving clc msg, the field length in smc_clc_msg_hdr indicates the length of msg should be received from network and the value should not be fully trusted as it is from the network. Once the value of length exceeds the value of buflen in function smc_clc_wait_msg it may run into deadloop when trying to drain the remaining data exceeding buflen. This patch checks the return value of sock_recvmsg when draining data in case of deadloop in draining.
Impacted products
Vendor Product Version
Linux Linux Version: fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1
Version: fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1
Version: fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1
Version: fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1
Version: fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1
Version: fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T20:54:28.243Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/smc/smc_clc.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "82c7ad9ca09975aae737abffd66d1ad98874c13d",
              "status": "affected",
              "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
              "versionType": "git"
            },
            {
              "lessThan": "6b80924af6216277892d5f091f5bfc7d1265fa28",
              "status": "affected",
              "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
              "versionType": "git"
            },
            {
              "lessThan": "d7d1f986ebb284b1db8dafca7d1bdb6dd2445cf6",
              "status": "affected",
              "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
              "versionType": "git"
            },
            {
              "lessThan": "7a6927814b4256d603e202ae7c5e38db3b338896",
              "status": "affected",
              "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
              "versionType": "git"
            },
            {
              "lessThan": "df3dfe1a93c6298d8c09a18e4fba19ef5b17763b",
              "status": "affected",
              "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
              "versionType": "git"
            },
            {
              "lessThan": "c5b8ee5022a19464783058dc6042e8eefa34e8cd",
              "status": "affected",
              "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/smc/smc_clc.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.8"
            },
            {
              "lessThan": "5.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.233",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.176",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.122",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.68",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.7",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.13",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.233",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.176",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.122",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.68",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.7",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13",
                  "versionStartIncluding": "5.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: check return value of sock_recvmsg when draining clc data\n\nWhen receiving clc msg, the field length in smc_clc_msg_hdr indicates the\nlength of msg should be received from network and the value should not be\nfully trusted as it is from the network. Once the value of length exceeds\nthe value of buflen in function smc_clc_wait_msg it may run into deadloop\nwhen trying to drain the remaining data exceeding buflen.\n\nThis patch checks the return value of sock_recvmsg when draining data in\ncase of deadloop in draining."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - SMC CLC handshake messages arrive over routable TCP/IP; the malicious `hdr.length` and the subsequent FIN/RST come entirely from a remote peer connecting to an SMC listener (or from a malicious server a client connects to). No adjacency requirement.\nAC:L - The attacker deterministically triggers the loop by sending a V2 CLC ACCEPT/CONFIRM/DECLINE header whose length field exceeds the receive buffer and then closing the socket; there is no race, no memory-layout dependency, and every input is attacker-controlled.\nPR:N - The CLC exchange is the very first thing processed after the TCP handshake and SMC performs no authentication whatsoever, so an unauthenticated remote peer reaches `smc_clc_wait_msg()` directly.\nUI:N - On the server side `smc_listen_work()` processes the crafted message automatically on connection acceptance; no local user action is needed.\nS:U - The hang is confined to the kernel\u0027s own security authority \u2014 a stuck workqueue worker/task and an SMC mutex; no boundary such as a VM or IOMMU domain is crossed.\nC:N - The drain loop reads into a bounded 100-byte stack buffer whose kvec `iov_len` caps every copy, and the discarded data is never returned to anyone; no memory contents are disclosed.\nI:N - No out-of-bounds write or state corruption occurs \u2014 even when `datlen` wraps negative, the kvec length bound prevents any overflow, so no data is modified.\nA:H - The unkillable infinite loop burns 100% of a CPU per connection while holding `lock_sock()` and, for SMC-R, the global `smc_server_lgr_pending` mutex, permanently wedging all SMC handshakes on the host; repeating it across connections exhausts every CPU and handshake worker."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:46:31.003Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/82c7ad9ca09975aae737abffd66d1ad98874c13d"
        },
        {
          "url": "https://git.kernel.org/stable/c/6b80924af6216277892d5f091f5bfc7d1265fa28"
        },
        {
          "url": "https://git.kernel.org/stable/c/d7d1f986ebb284b1db8dafca7d1bdb6dd2445cf6"
        },
        {
          "url": "https://git.kernel.org/stable/c/7a6927814b4256d603e202ae7c5e38db3b338896"
        },
        {
          "url": "https://git.kernel.org/stable/c/df3dfe1a93c6298d8c09a18e4fba19ef5b17763b"
        },
        {
          "url": "https://git.kernel.org/stable/c/c5b8ee5022a19464783058dc6042e8eefa34e8cd"
        }
      ],
      "title": "net/smc: check return value of sock_recvmsg when draining clc data",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-57791",
    "datePublished": "2025-01-11T12:35:48.905Z",
    "dateReserved": "2025-01-09T09:50:31.752Z",
    "dateUpdated": "2026-08-05T11:46:31.003Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…