{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-35901","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-05-17T13:50:33.114Z","datePublished":"2024-05-19T08:34:54.879Z","dateUpdated":"2026-08-05T11:30:52.091Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:30:52.091Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix Rx DMA datasize and skb_over_panic\n\nmana_get_rxbuf_cfg() aligns the RX buffer's DMA datasize to be\nmultiple of 64. So a packet slightly bigger than mtu+14, say 1536,\ncan be received and cause skb_over_panic.\n\nSample dmesg:\n[ 5325.237162] skbuff: skb_over_panic: text:ffffffffc043277a len:1536 put:1536 head:ff1100018b517000 data:ff1100018b517100 tail:0x700 end:0x6ea dev:<NULL>\n[ 5325.243689] ------------[ cut here ]------------\n[ 5325.245748] kernel BUG at net/core/skbuff.c:192!\n[ 5325.247838] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n[ 5325.258374] RIP: 0010:skb_panic+0x4f/0x60\n[ 5325.302941] Call Trace:\n[ 5325.304389]  <IRQ>\n[ 5325.315794]  ? skb_panic+0x4f/0x60\n[ 5325.317457]  ? asm_exc_invalid_op+0x1f/0x30\n[ 5325.319490]  ? skb_panic+0x4f/0x60\n[ 5325.321161]  skb_put+0x4e/0x50\n[ 5325.322670]  mana_poll+0x6fa/0xb50 [mana]\n[ 5325.324578]  __napi_poll+0x33/0x1e0\n[ 5325.326328]  net_rx_action+0x12e/0x280\n\nAs discussed internally, this alignment is not necessary. To fix\nthis bug, remove it from the code. So oversized packets will be\nmarked as CQE_RX_TRUNCATED by NIC, and dropped."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The bug is triggered purely by a received Ethernet frame processed in the MANA NIC's NAPI RX path, before any protocol demux or socket lookup, so a remote attacker anywhere on the routed network can reach it. On the very common Azure configuration where the VM MTU is set below the path MTU (VPN Gateway / ExpressRoute / AKS overlay guidance), ordinary full-size internet packets fall directly into the oversized window.\nAC:L - The attacker fully controls the only variable that matters — packet length — and can simply sweep sizes until one lands in the (mtu+14, ALIGN(mtu+14,64)] window, which is non-empty for the default MTU 1500. No race, no memory-layout grooming, and no state outside the attacker's control is involved.\nPR:N - No authentication or credentials of any kind are needed; the panic occurs in mana_build_skb() before eth_type_trans() and before netfilter, so the frame need not even be addressed to a listening service or survive a firewall rule. Any unauthenticated party able to send a frame to the interface triggers it.\nUI:N - Triggering requires only that the victim's interface be up and receiving; the panic happens in softirq context during normal packet reception with no action by any local user or administrator.\nS:U - The vulnerable code and the impacted resource are both the host kernel — a standard in-kernel crash with no crossing of a VM, IOMMU, or sandbox security authority.\nC:N - No data is disclosed to the attacker: the overlong DMA writes the attacker's own packet bytes into the buffer's skb_shared_info scratch area within the same allocation, and skb_over_panic() aborts immediately, so no kernel memory is read back or leaked over the wire.\nI:N - The excess DMA stays inside the allocated page/fragment, targets a region that is not a live object at DMA time and is re-zeroed by napi_build_skb(), and every packet reaching it hits the unconditional BUG() in the same call path — so no adjacent object is corrupted and no write primitive is obtained.\nA:H - skb_put() detects tail > end and calls skb_over_panic() → BUG() from within NAPI/softirq context, producing a fatal exception in interrupt and a full kernel panic. A single crafted packet takes the machine down, and it can be repeated at will against every affected Azure VM."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c","include/net/mana/mana.h"],"versions":[{"version":"2fbbd712baf1c60996554326728bbdbef5616e12","lessThan":"ca58927b00385005f488b6a9905ced7a4f719aad","status":"affected","versionType":"git"},{"version":"2fbbd712baf1c60996554326728bbdbef5616e12","lessThan":"05cb7c41fa1a7a7b2c2a6b81bbe7c67f5c11932b","status":"affected","versionType":"git"},{"version":"2fbbd712baf1c60996554326728bbdbef5616e12","lessThan":"c0de6ab920aafb56feab56058e46b688e694a246","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/microsoft/mana/mana_en.c","include/net/mana/mana.h"],"versions":[{"version":"6.4","status":"affected"},{"version":"0","lessThan":"6.4","status":"unaffected","versionType":"semver"},{"version":"6.6.26","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.8.5","lessThanOrEqual":"6.8.*","status":"unaffected","versionType":"semver"},{"version":"6.9","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.6.26"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.8.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.4","versionEndExcluding":"6.9"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/ca58927b00385005f488b6a9905ced7a4f719aad"},{"url":"https://git.kernel.org/stable/c/05cb7c41fa1a7a7b2c2a6b81bbe7c67f5c11932b"},{"url":"https://git.kernel.org/stable/c/c0de6ab920aafb56feab56058e46b688e694a246"}],"title":"net: mana: Fix Rx DMA datasize and skb_over_panic","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-35901","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-05-20T17:12:59.513048Z"}}}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:34:11.575Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T03:21:48.589Z"},"title":"CVE Program Container","references":[{"url":"https://git.kernel.org/stable/c/ca58927b00385005f488b6a9905ced7a4f719aad","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/05cb7c41fa1a7a7b2c2a6b81bbe7c67f5c11932b","tags":["x_transferred"]},{"url":"https://git.kernel.org/stable/c/c0de6ab920aafb56feab56058e46b688e694a246","tags":["x_transferred"]}]}]}}