Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-57973— rdma/cxgb4: Prevent potential integer overflow on 32bit

CVSS 8.1 · High EPSS 0.64% · P47

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux1cab775c3e75f1250c965feafd061d696df36e53< 2b759f78b83221f4a1cae3aeb20b500e375f3ee6affected
1cab775c3e75f1250c965feafd061d696df36e53< d64148a10a85952352de6091ceed99fb9ce2d3eeaffected
1cab775c3e75f1250c965feafd061d696df36e53< e53ca458f543aa352d09b484550de173cb9085c2affected
1cab775c3e75f1250c965feafd061d696df36e53< 4422f452d028850b9cc4fd8f1cf45a8ff91855ebaffected
1cab775c3e75f1250c965feafd061d696df36e53< de8d88b68d0cfd41152a7a63d6aec0ed3e1b837aaffected
1cab775c3e75f1250c965feafd061d696df36e53< dd352107f22bfbecbbf3b74bde14f3f932296309affected
1cab775c3e75f1250c965feafd061d696df36e53< aeb814484387811b3579d5c78ad4eb301e3bf1c8affected
1cab775c3e75f1250c965feafd061d696df36e53< bd96a3935e89486304461a21752f824fc25e0f0baffected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-57973

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
rdma/cxgb4: Prevent potential integer overflow on 32bit
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl->tot_len + sizeof(struct cpl_pass_accept_req) + sizeof(struct rss_header)" addition could have an integer wrapping bug. Use size_add() to prevent this.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于cxgb4驱动存在潜在整数溢出。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 1cab775c3e75f1250c965feafd061d696df36e53 ~ 2b759f78b83221f4a1cae3aeb20b500e375f3ee6 -
LinuxLinux 3.8 -

II. Public POCs for CVE-2024-57973

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-57973

登录查看更多情报信息。

Patches & Fixes for CVE-2024-57973 (5)

Other References for CVE-2024-57973 (2)

Same Patch Batch · Linux · 2025-02-27 · 177 CVEs total

CVE-2025-217489.8 CRITICALksmbd: fix integer overflows on 32 bit systems
CVE-2025-218059.8 CRITICALRDMA/rtrs: Add missing deinit() call
CVE-2025-217079.8 CRITICALmptcp: consolidate suboption status
CVE-2025-217969.8 CRITICALnfsd: clear acl_access/acl_default after releasing them
CVE-2024-580069.6 CRITICALPCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()
CVE-2024-579998.8 HIGHpowerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW
CVE-2024-579978.8 HIGHwifi: wcn36xx: fix channel survey memory allocation size
CVE-2024-579958.8 HIGHwifi: ath12k: fix read pointer after free in ath12k_mac_assign_vif_to_vdev()
CVE-2025-217358.8 HIGHNFC: nci: Add bounds checking in nci_hci_create_pipe()
CVE-2025-217108.2 HIGHtcp: correct handling of extreme memory squeeze
CVE-2025-217668.1 HIGHipv4: use RCU protection in __ip_rt_update_pmtu()
CVE-2025-217608.1 HIGHndisc: extend RCU protection in ndisc_send_skb()
CVE-2025-217628.1 HIGHarp: use RCU protection in arp_xmit()
CVE-2025-217658.1 HIGHipv6: use RCU protection in ip6_default_advmss()
CVE-2025-217347.8 HIGHmisc: fastrpc: Fix copy buffer page size
CVE-2025-217517.8 HIGHnet/mlx5: HWS, change error flow on matcher disconnect
CVE-2024-580027.8 HIGHmedia: uvcvideo: Remove dangling pointers
CVE-2025-217227.8 HIGHnilfs2: do not force clear folio if buffer is referenced
CVE-2024-525607.8 HIGHfs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()
CVE-2025-217537.8 HIGHbtrfs: fix use-after-free when attempting to join an aborted transaction

Showing top 20 of 177 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-57973

No comments yet


Leave a comment