CVE-2024-47408

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-47408
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47408.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-47408
Downstream
Related
Published
2025-01-11T12:35:35.284Z
Modified
2025-11-27T19:35:34.520180Z
Summary
net/smc: check smcd_v2_ext_offset when receiving proposal msg
Details

In the Linux kernel, the following vulnerability has been resolved:

net/smc: check smcdv2ext_offset when receiving proposal msg

When receiving proposal msg in server, the field smcdv2extoffset in proposal msg is from the remote client and can not be fully trusted. Once the value of smcdv2extoffset exceed the max value, there has the chance to access wrong address, and crash may happen.

This patch checks the value of smcdv2ext_offset before using it.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/blob/ee626f5d79d5817bb21d6f048dc0da4c4e383443/cves/2024/47xxx/CVE-2024-47408.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5c21c4ccafe85906db809de3af391fd434df8a27
Fixed
a36364d8d4fabb105001f992fb8ff2d3546203d6
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5c21c4ccafe85906db809de3af391fd434df8a27
Fixed
e1cc8be2a785a8f1ce1f597f3e608602c5fccd46
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5c21c4ccafe85906db809de3af391fd434df8a27
Fixed
935caf324b445fe73d7708fae6f7176fb243f357
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5c21c4ccafe85906db809de3af391fd434df8a27
Fixed
48d5a8a304a643613dab376a278f29d3e22f7c34
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5c21c4ccafe85906db809de3af391fd434df8a27
Fixed
9ab332deb671d8f7e66d82a2ff2b3f715bc3a4ad

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.10.0
Fixed
5.15.176
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.122
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.68
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.7