CVE-2024-57973

Source
https://cve.org/CVERecord?id=CVE-2024-57973
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-57973.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-57973
Downstream
Related
Published
2025-02-27T02:07:02.342Z
Modified
2026-05-07T04:18:17.134594Z
Summary
rdma/cxgb4: Prevent potential integer overflow on 32bit
Details

In the Linux kernel, the following vulnerability has been resolved:

rdma/cxgb4: Prevent potential integer overflow on 32bit

The "gl->totlen" variable is controlled by the user. It comes from processresponses(). On 32bit systems, the "gl->totlen + sizeof(struct cplpassacceptreq) + sizeof(struct rssheader)" addition could have an integer wrapping bug. Use sizeadd() to prevent this.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/57xxx/CVE-2024-57973.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1cab775c3e75f1250c965feafd061d696df36e53
Fixed
2b759f78b83221f4a1cae3aeb20b500e375f3ee6
Fixed
d64148a10a85952352de6091ceed99fb9ce2d3ee
Fixed
e53ca458f543aa352d09b484550de173cb9085c2
Fixed
4422f452d028850b9cc4fd8f1cf45a8ff91855eb
Fixed
de8d88b68d0cfd41152a7a63d6aec0ed3e1b837a
Fixed
dd352107f22bfbecbbf3b74bde14f3f932296309
Fixed
aeb814484387811b3579d5c78ad4eb301e3bf1c8
Fixed
bd96a3935e89486304461a21752f824fc25e0f0b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-57973.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.8.0
Fixed
5.4.291
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.235
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.179
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.129
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.76
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.13
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-57973.json"