CVE-2024-57973 (GCVE-0-2024-57973)
Vulnerability from cvelistv5
Published
2025-02-27 02:07
Modified
2026-08-05 11:47
Summary
In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl->tot_len + sizeof(struct cpl_pass_accept_req) + sizeof(struct rss_header)" addition could have an integer wrapping bug. Use size_add() to prevent this.
Impacted products
Vendor Product Version
Linux Linux Version: 1cab775c3e75f1250c965feafd061d696df36e53
Version: 1cab775c3e75f1250c965feafd061d696df36e53
Version: 1cab775c3e75f1250c965feafd061d696df36e53
Version: 1cab775c3e75f1250c965feafd061d696df36e53
Version: 1cab775c3e75f1250c965feafd061d696df36e53
Version: 1cab775c3e75f1250c965feafd061d696df36e53
Version: 1cab775c3e75f1250c965feafd061d696df36e53
Version: 1cab775c3e75f1250c965feafd061d696df36e53
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2025-11-03T19:32:49.370Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
          },
          {
            "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          },
          {
            "defaultStatus": "unknown",
            "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "*",
                "status": "affected",
                "version": "V3.1.6",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-14T12:38:44.721Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/hw/cxgb4/device.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "2b759f78b83221f4a1cae3aeb20b500e375f3ee6",
              "status": "affected",
              "version": "1cab775c3e75f1250c965feafd061d696df36e53",
              "versionType": "git"
            },
            {
              "lessThan": "d64148a10a85952352de6091ceed99fb9ce2d3ee",
              "status": "affected",
              "version": "1cab775c3e75f1250c965feafd061d696df36e53",
              "versionType": "git"
            },
            {
              "lessThan": "e53ca458f543aa352d09b484550de173cb9085c2",
              "status": "affected",
              "version": "1cab775c3e75f1250c965feafd061d696df36e53",
              "versionType": "git"
            },
            {
              "lessThan": "4422f452d028850b9cc4fd8f1cf45a8ff91855eb",
              "status": "affected",
              "version": "1cab775c3e75f1250c965feafd061d696df36e53",
              "versionType": "git"
            },
            {
              "lessThan": "de8d88b68d0cfd41152a7a63d6aec0ed3e1b837a",
              "status": "affected",
              "version": "1cab775c3e75f1250c965feafd061d696df36e53",
              "versionType": "git"
            },
            {
              "lessThan": "dd352107f22bfbecbbf3b74bde14f3f932296309",
              "status": "affected",
              "version": "1cab775c3e75f1250c965feafd061d696df36e53",
              "versionType": "git"
            },
            {
              "lessThan": "aeb814484387811b3579d5c78ad4eb301e3bf1c8",
              "status": "affected",
              "version": "1cab775c3e75f1250c965feafd061d696df36e53",
              "versionType": "git"
            },
            {
              "lessThan": "bd96a3935e89486304461a21752f824fc25e0f0b",
              "status": "affected",
              "version": "1cab775c3e75f1250c965feafd061d696df36e53",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/infiniband/hw/cxgb4/device.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.8"
            },
            {
              "lessThan": "3.8",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.4.*",
              "status": "unaffected",
              "version": "5.4.291",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.235",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.179",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.129",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.76",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.14",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.4.291",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.235",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.179",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.129",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.76",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.13",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.2",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14",
                  "versionStartIncluding": "3.8",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrdma/cxgb4: Prevent potential integer overflow on 32bit\n\nThe \"gl-\u003etot_len\" variable is controlled by the user.  It comes from\nprocess_responses().  On 32bit systems, the \"gl-\u003etot_len + sizeof(struct\ncpl_pass_accept_req) + sizeof(struct rss_header)\" addition could have an\ninteger wrapping bug.  Use size_add() to prevent this."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable `copy_gl_to_skb_pkt()` is invoked from the cxgb4 ingress-queue handler for `CPL_RX_PKT` frames, which the hardware server filter delivers for incoming TCP SYN packets addressed to an iWARP listening endpoint. The length value and the copied payload both originate from a remote peer\u0027s packet on the wire.\nAC:H - The addition can only wrap if `gl-\u003etot_len` approaches 2^32, but `RSPD_LEN_M` masks the hardware-reported length to 31 bits and the SGE fragment loop bounds it to real received packet data, so the attacker cannot supply a wrapping value. It additionally requires a 32-bit kernel hosting a Chelsio T4/T5 RDMA adapter \u2014 a rare configuration entirely outside the attacker\u0027s control.\nPR:N - The path is reached during passive-open connection setup from an inbound SYN, before any iWARP/RDMA connection is established or any credentials are exchanged. An unauthenticated remote host is sufficient.\nUI:N - Packet processing happens in the NAPI/interrupt receive path with no user action required; the administrator merely having an iWARP listener bound is a deployment precondition, not victim interaction.\nS:U - The overflow corrupts kernel slab memory within the same kernel security authority, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - An undersized `alloc_skb()` followed by `__skb_put()` of the full unwrapped length leaves the skb describing memory beyond its allocation, so subsequent processing of that skb reads adjacent slab contents, and the resulting heap corruption is leverageable for arbitrary kernel memory disclosure.\nI:H - `skb_copy_to_linear_data_offset()` writes attacker-supplied packet bytes past the end of the undersized allocation, giving a controlled-content heap buffer overflow suitable for corrupting adjacent objects and hijacking control flow.\nA:H - Overwriting adjacent slab objects with wire data reliably corrupts kernel state and panics the machine, and the allocation of a near-2GB skb would itself destabilize the system under GFP_ATOMIC in the receive path."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:47:04.121Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2b759f78b83221f4a1cae3aeb20b500e375f3ee6"
        },
        {
          "url": "https://git.kernel.org/stable/c/d64148a10a85952352de6091ceed99fb9ce2d3ee"
        },
        {
          "url": "https://git.kernel.org/stable/c/e53ca458f543aa352d09b484550de173cb9085c2"
        },
        {
          "url": "https://git.kernel.org/stable/c/4422f452d028850b9cc4fd8f1cf45a8ff91855eb"
        },
        {
          "url": "https://git.kernel.org/stable/c/de8d88b68d0cfd41152a7a63d6aec0ed3e1b837a"
        },
        {
          "url": "https://git.kernel.org/stable/c/dd352107f22bfbecbbf3b74bde14f3f932296309"
        },
        {
          "url": "https://git.kernel.org/stable/c/aeb814484387811b3579d5c78ad4eb301e3bf1c8"
        },
        {
          "url": "https://git.kernel.org/stable/c/bd96a3935e89486304461a21752f824fc25e0f0b"
        }
      ],
      "title": "rdma/cxgb4: Prevent potential integer overflow on 32bit",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2024-57973",
    "datePublished": "2025-02-27T02:07:02.342Z",
    "dateReserved": "2025-02-27T02:04:28.911Z",
    "dateUpdated": "2026-08-05T11:47:04.121Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…