« Volver al listado

CVE-2023-54094

Estado: AplazadaCrítica (9.8)—

In the Linux kernel, the following vulnerability has been resolved:

net: prevent skb corruption on frag list segmentation

Ian reported several skb corruptions triggered by rx-gro-list, collecting different oops alike:

In the critical scenario, rx-gro-list GRO-ed packets are fed, via a bridge, both to the local input path and to an egress device (tun).

The segmentation of such packets unsafely writes to the cloned skbs with shared heads.

This change addresses the issue by uncloning as needed the to-be-segmented skbs.

Detalles técnicos trazas, registros y código del informe original
[   62.624003] BUG: kernel NULL pointer dereference, address: 00000000000000c0
[   62.631083] #PF: supervisor read access in kernel mode
[   62.636312] #PF: error_code(0x0000) - not-present page
[   62.641541] PGD 0 P4D 0
[   62.644174] Oops: 0000 [#1] PREEMPT SMP NOPTI
[   62.648629] CPU: 1 PID: 913 Comm: napi/eno2-79 Not tainted 6.4.0 #364
[   62.655162] Hardware name: Supermicro Super Server/A2SDi-12C-HLN4F, BIOS 1.7a 10/13/2022
[   62.663344] RIP: 0010:__udp_gso_segment (./include/linux/skbuff.h:2858
./include/linux/udp.h:23 net/ipv4/udp_offload.c:228 net/ipv4/udp_offload.c:261
net/ipv4/udp_offload.c:277)
[   62.687193] RSP: 0018:ffffbd3a83b4f868 EFLAGS: 00010246
[   62.692515] RAX: 00000000000000ce RBX: 0000000000000000 RCX: 0000000000000000
[   62.699743] RDX: ffffa124def8a000 RSI: 0000000000000079 RDI: ffffa125952a14d4
[   62.706970] RBP: ffffa124def8a000 R08: 0000000000000022 R09: 00002000001558c9
[   62.714199] R10: 0000000000000000 R11: 00000000be554639 R12: 00000000000000e2
[   62.721426] R13: ffffa125952a1400 R14: ffffa125952a1400 R15: 00002000001558c9
[   62.728654] FS:  0000000000000000(0000) GS:ffffa127efa40000(0000)
knlGS:0000000000000000
[   62.736852] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[   62.742702] CR2: 00000000000000c0 CR3: 00000001034b0000 CR4: 00000000003526e0
[   62.749948] Call Trace:
[   62.752498]  <TASK>
[   62.779267] inet_gso_segment (net/ipv4/af_inet.c:1398)
[   62.787605] skb_mac_gso_segment (net/core/gro.c:141)
[   62.791906] __skb_gso_segment (net/core/dev.c:3403 (discriminator 2))
[   62.800492] validate_xmit_skb (./include/linux/netdevice.h:4862
net/core/dev.c:3659)
[   62.804695] validate_xmit_skb_list (net/core/dev.c:3710)
[   62.809158] sch_direct_xmit (net/sched/sch_generic.c:330)
[   62.813198] __dev_queue_xmit (net/core/dev.c:3805 net/core/dev.c:4210)
net/netfilter/core.c:626)
[   62.821093] br_dev_queue_push_xmit (net/bridge/br_forward.c:55)
[   62.825652] maybe_deliver (net/bridge/br_forward.c:193)
[   62.829420] br_flood (net/bridge/br_forward.c:233)
[   62.832758] br_handle_frame_finish (net/bridge/br_input.c:215)
[   62.837403] br_handle_frame (net/bridge/br_input.c:298
net/bridge/br_input.c:416)
[   62.851417] __netif_receive_skb_core.constprop.0 (net/core/dev.c:5387)
[   62.866114] __netif_receive_skb_list_core (net/core/dev.c:5570)
[   62.871367] netif_receive_skb_list_internal (net/core/dev.c:5638
net/core/dev.c:5727)
[   62.876795] napi_complete_done (./include/linux/list.h:37
./include/net/gro.h:434 ./include/net/gro.h:429 net/core/dev.c:6067)
[   62.881004] ixgbe_poll (drivers/net/ethernet/intel/ixgbe/ixgbe_main.c:3191)
[   62.893534] __napi_poll (net/core/dev.c:6498)
[   62.897133] napi_threaded_poll (./include/linux/netpoll.h:89
net/core/dev.c:6640)
[   62.905276] kthread (kernel/kthread.c:379)
[   62.913435] ret_from_fork (arch/x86/entry/entry_64.S:314)
[   62.917119]  </TASK>

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad remota (AV:N, PR:N, UI:N) en segmentación de paquetes del kernel Linux que causa corrupción de memoria y crashes (NULL pointer dereference). Permite DoS y potencial escalada local.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-54094",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
              "lessThan": "bc3ab5d2ab69823f5cff89cf74ef78ffa0386c9a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
              "lessThan": "ea438eed94ac0fe69b93ac034738823c0e989a12",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
              "lessThan": "1731234e8b60063eae858c77b55c7a88f5084353",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
              "lessThan": "7a59f29961cf97b98b02acaadf5a0b1f8dde938c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3a1296a38d0cf62bffb9a03c585cbd5dbf15d596",
              "lessThan": "c329b261afe71197d9da83c1f18eb45a7e97e089",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/core/skbuff.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.188",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.121",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.4.5",
              "versionType": "semver",
              "lessThanOrEqual": "6.4.*"
            },
            {
              "status": "unaffected",
              "version": "6.5",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/core/skbuff.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-12-24T13:16:11.280",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1731234e8b60063eae858c77b55c7a88f5084353",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7a59f29961cf97b98b02acaadf5a0b1f8dde938c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bc3ab5d2ab69823f5cff89cf74ef78ffa0386c9a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c329b261afe71197d9da83c1f18eb45a7e97e089",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ea438eed94ac0fe69b93ac034738823c0e989a12",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: prevent skb corruption on frag list segmentation\n\nIan reported several skb corruptions triggered by rx-gro-list,\ncollecting different oops alike:\n\n[   62.624003] BUG: kernel NULL pointer dereference, address: 00000000000000c0\n[   62.631083] #PF: supervisor read access in kernel mode\n[   62.636312] #PF: error_code(0x0000) - not-present page\n[   62.641541] PGD 0 P4D 0\n[   62.644174] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[   62.648629] CPU: 1 PID: 913 Comm: napi/eno2-79 Not tainted 6.4.0 #364\n[   62.655162] Hardware name: Supermicro Super Server/A2SDi-12C-HLN4F, BIOS 1.7a 10/13/2022\n[   62.663344] RIP: 0010:__udp_gso_segment (./include/linux/skbuff.h:2858\n./include/linux/udp.h:23 net/ipv4/udp_offload.c:228 net/ipv4/udp_offload.c:261\nnet/ipv4/udp_offload.c:277)\n[   62.687193] RSP: 0018:ffffbd3a83b4f868 EFLAGS: 00010246\n[   62.692515] RAX: 00000000000000ce RBX: 0000000000000000 RCX: 0000000000000000\n[   62.699743] RDX: ffffa124def8a000 RSI: 0000000000000079 RDI: ffffa125952a14d4\n[   62.706970] RBP: ffffa124def8a000 R08: 0000000000000022 R09: 00002000001558c9\n[   62.714199] R10: 0000000000000000 R11: 00000000be554639 R12: 00000000000000e2\n[   62.721426] R13: ffffa125952a1400 R14: ffffa125952a1400 R15: 00002000001558c9\n[   62.728654] FS:  0000000000000000(0000) GS:ffffa127efa40000(0000)\nknlGS:0000000000000000\n[   62.736852] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[   62.742702] CR2: 00000000000000c0 CR3: 00000001034b0000 CR4: 00000000003526e0\n[   62.749948] Call Trace:\n[   62.752498]  <TASK>\n[   62.779267] inet_gso_segment (net/ipv4/af_inet.c:1398)\n[   62.787605] skb_mac_gso_segment (net/core/gro.c:141)\n[   62.791906] __skb_gso_segment (net/core/dev.c:3403 (discriminator 2))\n[   62.800492] validate_xmit_skb (./include/linux/netdevice.h:4862\nnet/core/dev.c:3659)\n[   62.804695] validate_xmit_skb_list (net/core/dev.c:3710)\n[   62.809158] sch_direct_xmit (net/sched/sch_generic.c:330)\n[   62.813198] __dev_queue_xmit (net/core/dev.c:3805 net/core/dev.c:4210)\nnet/netfilter/core.c:626)\n[   62.821093] br_dev_queue_push_xmit (net/bridge/br_forward.c:55)\n[   62.825652] maybe_deliver (net/bridge/br_forward.c:193)\n[   62.829420] br_flood (net/bridge/br_forward.c:233)\n[   62.832758] br_handle_frame_finish (net/bridge/br_input.c:215)\n[   62.837403] br_handle_frame (net/bridge/br_input.c:298\nnet/bridge/br_input.c:416)\n[   62.851417] __netif_receive_skb_core.constprop.0 (net/core/dev.c:5387)\n[   62.866114] __netif_receive_skb_list_core (net/core/dev.c:5570)\n[   62.871367] netif_receive_skb_list_internal (net/core/dev.c:5638\nnet/core/dev.c:5727)\n[   62.876795] napi_complete_done (./include/linux/list.h:37\n./include/net/gro.h:434 ./include/net/gro.h:429 net/core/dev.c:6067)\n[   62.881004] ixgbe_poll (drivers/net/ethernet/intel/ixgbe/ixgbe_main.c:3191)\n[   62.893534] __napi_poll (net/core/dev.c:6498)\n[   62.897133] napi_threaded_poll (./include/linux/netpoll.h:89\nnet/core/dev.c:6640)\n[   62.905276] kthread (kernel/kthread.c:379)\n[   62.913435] ret_from_fork (arch/x86/entry/entry_64.S:314)\n[   62.917119]  </TASK>\n\nIn the critical scenario, rx-gro-list GRO-ed packets are fed, via a\nbridge, both to the local input path and to an egress device (tun).\n\nThe segmentation of such packets unsafely writes to the cloned skbs\nwith shared heads.\n\nThis change addresses the issue by uncloning as needed the\nto-be-segmented skbs."
    }
  ],
  "lastModified": "2026-08-04T10:19:28.733",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}