CVE-2024-41091
Linux Linux, linux kernel
In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tun_xdp_one() path, which could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tun_xdp_one-->eth_type_trans() may access the Ethernet header although it can be less than ETH_HLEN. Once transmitted, this could either cause out-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata. In th...
- CVSS
- 7.1
- EPSS
- 0.25% 16.9% percentile
- CISA KEV
- Not listed
- Published
- 2024.07.29