{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2024-26857","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-02-19T14:20:24.183Z","datePublished":"2024-04-17T10:17:19.115Z","dateUpdated":"2026-08-05T11:27:51.379Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:27:51.379Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: make sure to pull inner header in geneve_rx()\n\nsyzbot triggered a bug in geneve_rx() [1]\n\nIssue is similar to the one I fixed in commit 8d975c15c0cd\n(\"ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()\")\n\nWe have to save skb->network_header in a temporary variable\nin order to be able to recompute the network_header pointer\nafter a pskb_inet_may_pull() call.\n\npskb_inet_may_pull() makes sure the needed headers are in skb->head.\n\n[1]\nBUG: KMSAN: uninit-value in IP_ECN_decapsulate include/net/inet_ecn.h:302 [inline]\n BUG: KMSAN: uninit-value in geneve_rx drivers/net/geneve.c:279 [inline]\n BUG: KMSAN: uninit-value in geneve_udp_encap_recv+0x36f9/0x3c10 drivers/net/geneve.c:391\n  IP_ECN_decapsulate include/net/inet_ecn.h:302 [inline]\n  geneve_rx drivers/net/geneve.c:279 [inline]\n  geneve_udp_encap_recv+0x36f9/0x3c10 drivers/net/geneve.c:391\n  udp_queue_rcv_one_skb+0x1d39/0x1f20 net/ipv4/udp.c:2108\n  udp_queue_rcv_skb+0x6ae/0x6e0 net/ipv4/udp.c:2186\n  udp_unicast_rcv_skb+0x184/0x4b0 net/ipv4/udp.c:2346\n  __udp4_lib_rcv+0x1c6b/0x3010 net/ipv4/udp.c:2422\n  udp_rcv+0x7d/0xa0 net/ipv4/udp.c:2604\n  ip_protocol_deliver_rcu+0x264/0x1300 net/ipv4/ip_input.c:205\n  ip_local_deliver_finish+0x2b8/0x440 net/ipv4/ip_input.c:233\n  NF_HOOK include/linux/netfilter.h:314 [inline]\n  ip_local_deliver+0x21f/0x490 net/ipv4/ip_input.c:254\n  dst_input include/net/dst.h:461 [inline]\n  ip_rcv_finish net/ipv4/ip_input.c:449 [inline]\n  NF_HOOK include/linux/netfilter.h:314 [inline]\n  ip_rcv+0x46f/0x760 net/ipv4/ip_input.c:569\n  __netif_receive_skb_one_core net/core/dev.c:5534 [inline]\n  __netif_receive_skb+0x1a6/0x5a0 net/core/dev.c:5648\n  process_backlog+0x480/0x8b0 net/core/dev.c:5976\n  __napi_poll+0xe3/0x980 net/core/dev.c:6576\n  napi_poll net/core/dev.c:6645 [inline]\n  net_rx_action+0x8b8/0x1870 net/core/dev.c:6778\n  __do_softirq+0x1b7/0x7c5 kernel/softirq.c:553\n  do_softirq+0x9a/0xf0 kernel/softirq.c:454\n  __local_bh_enable_ip+0x9b/0xa0 kernel/softirq.c:381\n  local_bh_enable include/linux/bottom_half.h:33 [inline]\n  rcu_read_unlock_bh include/linux/rcupdate.h:820 [inline]\n  __dev_queue_xmit+0x2768/0x51c0 net/core/dev.c:4378\n  dev_queue_xmit include/linux/netdevice.h:3171 [inline]\n  packet_xmit+0x9c/0x6b0 net/packet/af_packet.c:276\n  packet_snd net/packet/af_packet.c:3081 [inline]\n  packet_sendmsg+0x8aef/0x9f10 net/packet/af_packet.c:3113\n  sock_sendmsg_nosec net/socket.c:730 [inline]\n  __sock_sendmsg net/socket.c:745 [inline]\n  __sys_sendto+0x735/0xa10 net/socket.c:2191\n  __do_sys_sendto net/socket.c:2203 [inline]\n  __se_sys_sendto net/socket.c:2199 [inline]\n  __x64_sys_sendto+0x125/0x1c0 net/socket.c:2199\n  do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n  do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\n  slab_post_alloc_hook mm/slub.c:3819 [inline]\n  slab_alloc_node mm/slub.c:3860 [inline]\n  kmem_cache_alloc_node+0x5cb/0xbc0 mm/slub.c:3903\n  kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560\n  __alloc_skb+0x352/0x790 net/core/skbuff.c:651\n  alloc_skb include/linux/skbuff.h:1296 [inline]\n  alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6394\n  sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2783\n  packet_alloc_skb net/packet/af_packet.c:2930 [inline]\n  packet_snd net/packet/af_packet.c:3024 [inline]\n  packet_sendmsg+0x70c2/0x9f10 net/packet/af_packet.c:3113\n  sock_sendmsg_nosec net/socket.c:730 [inline]\n  __sock_sendmsg net/socket.c:745 [inline]\n  __sys_sendto+0x735/0xa10 net/socket.c:2191\n  __do_sys_sendto net/socket.c:2203 [inline]\n  __se_sys_sendto net/socket.c:2199 [inline]\n  __x64_sys_sendto+0x125/0x1c0 net/socket.c:2199\n  do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n  do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":7.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable code is the GENEVE UDP encapsulation receive handler for a socket bound to INADDR_ANY on UDP port 6081, reached directly from `udp_rcv()` on a received packet. In collect_md/external mode (standard OVS/OVN cloud overlay) `geneve_lookup_skb()` accepts any remote source address, so any host that can send UDP to the tunnel endpoint reaches `geneve_rx()`.\nAC:L - The attacker fully controls the skb layout: sending the encapsulated packet as IP fragments makes `ip_defrag()` produce a frag_list skb whose linear area ends exactly at the inner Ethernet header, deterministically placing `skb->data` at `skb->tail` before the ECN read. Outer IP options and geneve option length give additional 4-byte tuning for NIC-driven fragment layouts.\nPR:N - There is no authentication, capability check, or credential validation anywhere on the `ip_rcv` → `udp_rcv` → `geneve_udp_encap_recv` → `geneve_rx` path. An unauthenticated remote peer only needs to send a crafted UDP datagram to the tunnel port.\nUI:N - The bug triggers entirely during softirq packet receive processing on the target host; no local user has to open, mount, or interact with anything.\nS:U - The uninitialized read occurs in kernel network receive context and its effects (ECN decision, packet drop) stay within the kernel's own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:L - The bug reads uninitialized kernel heap memory past the end of the valid skb data, but is strictly bounded to 1 byte (IPv4 TOS) or 2 bytes (IPv6 dsfield) and stays inside the `skb->head` allocation. The stale contents are not returned to the attacker directly — they leak only as a per-packet drop/no-drop oracle from `__INET_ECN_decapsulate()`.\nI:L - The uninitialized byte drives whether the decapsulated packet is dropped and whether CE/ECT(1) marking is applied to tunneled traffic, so data traversing the tunnel can be modified or discarded based on garbage. The amount is minimal and the attacker has no control over the consequence; `INET_ECN_set_ce()`/`set_ect1()` are bounds-checked, so no out-of-bounds write primitive exists.\nA:L - Incorrect ECN decapsulation driven by uninitialized memory causes spurious drops of legitimate GENEVE-tunneled traffic (`err > 1` → `kfree_skb`), degrading overlay connectivity. There is no kernel crash on production configurations — the read stays within the `skb->head` slab object so KASAN does not fire, and only the KMSAN debug tool reports it."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/geneve.c"],"versions":[{"version":"2d07dc79fe04a43d82a346ced6bbf07bdb523f1b","lessThan":"e431c3227864b5646601c97f5f898d99472f2914","status":"affected","versionType":"git"},{"version":"2d07dc79fe04a43d82a346ced6bbf07bdb523f1b","lessThan":"59d2a4076983303f324557a114cfd5c32e1f6b29","status":"affected","versionType":"git"},{"version":"2d07dc79fe04a43d82a346ced6bbf07bdb523f1b","lessThan":"c7137900691f5692fe3de54566ea7b30bb35d66c","status":"affected","versionType":"git"},{"version":"2d07dc79fe04a43d82a346ced6bbf07bdb523f1b","lessThan":"e77e0b0f2a11735c64b105edaee54d6344faca8a","status":"affected","versionType":"git"},{"version":"2d07dc79fe04a43d82a346ced6bbf07bdb523f1b","lessThan":"c0b22568a9d8384fd000cc49acb8f74bde40d1b5","status":"affected","versionType":"git"},{"version":"2d07dc79fe04a43d82a346ced6bbf07bdb523f1b","lessThan":"0ece581d2a66e8e488c0d3b3e7b5760dbbfdbdd5","status":"affected","versionType":"git"},{"version":"2d07dc79fe04a43d82a346ced6bbf07bdb523f1b","lessThan":"048e16dee1fc609c1c85072ccd70bfd4b5fef6ca","status":"affected","versionType":"git"},{"version":"2d07dc79fe04a43d82a346ced6bbf07bdb523f1b","lessThan":"1ca1ba465e55b9460e4e75dec9fff31e708fec74","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/geneve.c"],"versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","status":"unaffected","versionType":"semver"},{"version":"4.19.310","lessThanOrEqual":"4.19.*","status":"unaffected","versionType":"semver"},{"version":"5.4.272","lessThanOrEqual":"5.4.*","status":"unaffected","versionType":"semver"},{"version":"5.10.213","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.152","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.82","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.22","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.7.10","lessThanOrEqual":"6.7.*","status":"unaffected","versionType":"semver"},{"version":"6.8","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"4.19.310"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.4.272"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.10.213"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"5.15.152"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.1.82"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.6.22"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.7.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.8"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e431c3227864b5646601c97f5f898d99472f2914"},{"url":"https://git.kernel.org/stable/c/59d2a4076983303f324557a114cfd5c32e1f6b29"},{"url":"https://git.kernel.org/stable/c/c7137900691f5692fe3de54566ea7b30bb35d66c"},{"url":"https://git.kernel.org/stable/c/e77e0b0f2a11735c64b105edaee54d6344faca8a"},{"url":"https://git.kernel.org/stable/c/c0b22568a9d8384fd000cc49acb8f74bde40d1b5"},{"url":"https://git.kernel.org/stable/c/0ece581d2a66e8e488c0d3b3e7b5760dbbfdbdd5"},{"url":"https://git.kernel.org/stable/c/048e16dee1fc609c1c85072ccd70bfd4b5fef6ca"},{"url":"https://git.kernel.org/stable/c/1ca1ba465e55b9460e4e75dec9fff31e708fec74"}],"title":"geneve: make sure to pull inner header in geneve_rx()","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-noinfo Not enough information"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-06-12T17:32:22.775976Z","id":"CVE-2024-26857","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-06T16:53:14.290Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T00:14:13.648Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/e431c3227864b5646601c97f5f898d99472f2914","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/59d2a4076983303f324557a114cfd5c32e1f6b29","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/c7137900691f5692fe3de54566ea7b30bb35d66c","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/e77e0b0f2a11735c64b105edaee54d6344faca8a","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/c0b22568a9d8384fd000cc49acb8f74bde40d1b5","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/0ece581d2a66e8e488c0d3b3e7b5760dbbfdbdd5","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/048e16dee1fc609c1c85072ccd70bfd4b5fef6ca","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/1ca1ba465e55b9460e4e75dec9fff31e708fec74","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html","tags":["x_transferred"]}]}]},"dataVersion":"5.2"}