CVE-2024-44940

high

Description

In the Linux kernel, the following vulnerability has been resolved: fou: remove warn in gue_gro_receive on unsupported protocol Drop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is not known or does not have a GRO handler. Such a packet is easily constructed. Syzbot generates them and sets off this warning. Remove the warning as it is expected and not actionable. The warning was previously reduced from WARN_ON to WARN_ON_ONCE in commit 270136613bf7 ("fou: Do WARN_ON_ONCE in gue_gro_receive for bad proto callbacks").

References

https://git.kernel.org/stable/c/dd89a81d850fa9a65f67b4527c0e420d15bf836c

https://git.kernel.org/stable/c/5a2e37bc648a2503bf6d687aed27b9f4455d82eb

https://git.kernel.org/stable/c/440ab7f97261bc28501636a13998e1b1946d2e79

https://git.kernel.org/stable/c/3db4395332e7050ef9ddeb3052e6b5019f2a2a59

Details

Source: Mitre, NVD

Published: 2024-08-26

Updated: 2024-09-12

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High