[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-35884":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":19,"aliases":20,"duplicate_of":9,"upstream":21,"downstream":22,"duplicates":77,"related":78,"reserved_at":9,"published_at":87,"modified_at":88,"state":89,"summary":90,"references_raw":99,"kevs":136,"epss":137,"epss_history":140,"metrics":403,"affected":416},"CVE-2024-35884","In the Linux kernel, the following vulnerability has been resolved:\n\nudp: do not accept non-tunnel GSO skbs landing in a tunnel\n\nWhen rx-udp-gro-forwarding is enabled UDP packets might be GROed when\nbeing forwarded. If such packets might land in a tunnel this can cause\nvarious issues and udp_gro_receive makes sure this isn't the case by\nlooking for a matching socket. This is performed in\nudp4/6_gro_lookup_skb but only in the current netns. This is an issue\nwith tunneled packets when the endpoint is in another netns. In such\ncases the packets will be GROed at the UDP level, which leads to various\nissues later on. The same thing can happen with rx-gro-list.\n\nWe saw this with geneve packets being GROed at the UDP level. In such\ncase gso_size is set; later the packet goes through the geneve rx path,\nthe geneve header is pulled, the offset are adjusted and frag_list skbs\nare not adjusted with regard to geneve. When those skbs hit\nskb_fragment, it will misbehave. Different outcomes are possible\ndepending on what the GROed skbs look like; from corrupted packets to\nkernel crashes.\n\nOne example is a BUG_ON[1] triggered in skb_segment while processing the\nfrag_list. Because gso_size is wrong (geneve header was pulled)\nskb_segment thinks there is \"geneve header size\" of data in frag_list,\nalthough it's in fact the next packet. The BUG_ON itself has nothing to\ndo with the issue. This is only one of the potential issues.\n\nLooking up for a matching socket in udp_gro_receive is fragile: the\nlookup could be extended to all netns (not speaking about performances)\nbut nothing prevents those packets from being modified in between and we\ncould still not find a matching socket. It's OK to keep the current\nlogic there as it should cover most cases but we also need to make sure\nwe handle tunnel packets being GROed too early.\n\nThis is done by extending the checks in udp_unexpected_gso: GSO packets\nlacking the SKB_GSO_UDP_TUNNEL/_CSUM bits and landing in a tunnel must\nbe segmented.\n\n[1] kernel BUG at net/core/skbuff.c:4408!\n    RIP: 0010:skb_segment+0xd2a/0xf70\n    __udp_gso_segment+0xaa/0x560",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-617","Reachable Assertion","The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.","weakness","Draft","Base",[],[],[],[],[23,25,27,29,31,33,35,37,39,41,43,45,47,49,51,53,55,57,59,61,63,65,67,69,71,73,75],{"_key":24},"SUSE-SU-2024:2571-1",{"_key":26},"SUSE-SU-2024:2372-1",{"_key":28},"SUSE-SU-2024:2394-1",{"_key":30},"SUSE-SU-2024:2896-1",{"_key":32},"SUSE-SU-2024:2939-1",{"_key":34},"SUSE-SU-2024:2973-1",{"_key":36},"DLA-3842-1",{"_key":38},"SUSE-SU-2025:20008-1",{"_key":40},"SUSE-SU-2025:20028-1",{"_key":42},"DEBIAN-CVE-2024-35884",{"_key":44},"RHSA-2024:7000",{"_key":46},"RHSA-2024:7001",{"_key":48},"RHSA-2024:8107",{"_key":50},"RHSA-2024:8161",{"_key":52},"UBUNTU-CVE-2024-35884",{"_key":54},"USN-6893-1",{"_key":56},"USN-6893-2",{"_key":58},"USN-6893-3",{"_key":60},"USN-6898-1",{"_key":62},"USN-6898-2",{"_key":64},"USN-6898-3",{"_key":66},"USN-6898-4",{"_key":68},"USN-6917-1",{"_key":70},"USN-6918-1",{"_key":72},"USN-6919-1",{"_key":74},"USN-6927-1",{"_key":76},"USN-7019-1",[],[79,80,81,82,83,84,85,86],{"_key":24},{"_key":26},{"_key":28},{"_key":30},{"_key":32},{"_key":34},{"_key":38},{"_key":40},"2024-05-19T08:34:40.948Z","2026-05-12T11:52:18.997Z","Modified",{"cisa_kev":91,"cisa_ransomware":91,"cisa_vendor":9,"epss_severity":92,"epss_score":93,"severity":94,"severity_score":95,"severity_version":96,"severity_source":97,"severity_vector":98,"severity_status":89},false,"low",0.00018,"high",8.8,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",[100,106,110,114,118,122,126,132],{"url":101,"sources":102,"tags":104},"https://git.kernel.org/stable/c/3391b157780bbedf8ef9f202cbf10ee90bf6b0f8",[97,103],"nvd",[105],"Patch",{"url":107,"sources":108,"tags":109},"https://git.kernel.org/stable/c/d49ae15a5767d4e9ef8bbb79e42df1bfebc94670",[97,103],[105],{"url":111,"sources":112,"tags":113},"https://git.kernel.org/stable/c/d12245080cb259d82b34699f6cd4ec11bdb688bd",[97,103],[105],{"url":115,"sources":116,"tags":117},"https://git.kernel.org/stable/c/3001e7aa43d6691db2a878b0745b854bf12ddd19",[97,103],[105],{"url":119,"sources":120,"tags":121},"https://git.kernel.org/stable/c/35fe0e0b5c00bef7dde74842a2564c43856fbce4",[97,103],[105],{"url":123,"sources":124,"tags":125},"https://git.kernel.org/stable/c/3d010c8031e39f5fa1e8b13ada77e0321091011f",[97,103],[105],{"url":127,"sources":128,"tags":129},"https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html",[97,103],[130,131],"X Transferred","Third Party Advisory",{"url":133,"sources":134,"tags":135},"https://cert-portal.siemens.com/productcert/html/ssa-265688.html",[97,103],[],[],{"date":138,"score":93,"percentile":139},"2026-06-03",0.04965,[141,145,148,151,154,157,160,163,166,169,172,175,178,181,185,189,192,195,198,201,204,207,210,213,216,219,222,225,228,231,234,237,240,243,245,248,251,254,257,260,263,266,269,272,275,278,281,284,287,290,293,297,300,302,305,308,311,314,317,320,323,326,329,332,335,338,340,343,346,349,352,355,357,360,362,365,367,370,373,376,379,382,384,386,388,390,392,394,397,400],{"date":142,"score":143,"percentile":144},"2025-11-04",0.00059,0.18445,{"date":146,"score":143,"percentile":147},"2025-11-05",0.18457,{"date":149,"score":143,"percentile":150},"2025-11-06",0.18467,{"date":152,"score":143,"percentile":153},"2025-11-07",0.18484,{"date":155,"score":143,"percentile":156},"2025-11-08",0.18486,{"date":158,"score":143,"percentile":159},"2025-11-09",0.18459,{"date":161,"score":143,"percentile":162},"2025-11-10",0.18419,{"date":164,"score":143,"percentile":165},"2025-11-11",0.18424,{"date":167,"score":143,"percentile":168},"2025-11-12",0.18462,{"date":170,"score":143,"percentile":171},"2025-11-13",0.18492,{"date":173,"score":143,"percentile":174},"2025-11-14",0.18482,{"date":176,"score":143,"percentile":177},"2025-11-15",0.18463,{"date":179,"score":143,"percentile":180},"2025-11-16",0.18426,{"date":182,"score":183,"percentile":184},"2025-11-17",0.00057,0.17773,{"date":186,"score":187,"percentile":188},"2025-11-18",0.00835,0.7259,{"date":190,"score":187,"percentile":191},"2025-11-19",0.72597,{"date":193,"score":187,"percentile":194},"2025-11-20",0.72606,{"date":196,"score":183,"percentile":197},"2025-11-21",0.17785,{"date":199,"score":183,"percentile":200},"2025-11-22",0.17799,{"date":202,"score":183,"percentile":203},"2025-11-23",0.17771,{"date":205,"score":183,"percentile":206},"2025-11-24",0.17737,{"date":208,"score":183,"percentile":209},"2025-11-25",0.17727,{"date":211,"score":183,"percentile":212},"2025-11-26",0.17722,{"date":214,"score":183,"percentile":215},"2025-11-27",0.17725,{"date":217,"score":183,"percentile":218},"2025-11-28",0.17715,{"date":220,"score":183,"percentile":221},"2025-11-29",0.17701,{"date":223,"score":183,"percentile":224},"2025-11-30",0.17704,{"date":226,"score":183,"percentile":227},"2025-12-01",0.17746,{"date":229,"score":183,"percentile":230},"2025-12-02",0.17755,{"date":232,"score":183,"percentile":233},"2025-12-03",0.17768,{"date":235,"score":183,"percentile":236},"2025-12-04",0.1773,{"date":238,"score":183,"percentile":239},"2025-12-05",0.17782,{"date":241,"score":183,"percentile":242},"2025-12-06",0.17787,{"date":244,"score":183,"percentile":233},"2025-12-07",{"date":246,"score":183,"percentile":247},"2025-12-08",0.1778,{"date":249,"score":183,"percentile":250},"2025-12-09",0.17847,{"date":252,"score":183,"percentile":253},"2025-12-10",0.1791,{"date":255,"score":183,"percentile":256},"2025-12-11",0.17957,{"date":258,"score":183,"percentile":259},"2025-12-12",0.18,{"date":261,"score":183,"percentile":262},"2025-12-13",0.18011,{"date":264,"score":183,"percentile":265},"2025-12-14",0.17958,{"date":267,"score":183,"percentile":268},"2025-12-15",0.17938,{"date":270,"score":183,"percentile":271},"2025-12-16",0.17972,{"date":273,"score":183,"percentile":274},"2025-12-17",0.18059,{"date":276,"score":183,"percentile":277},"2025-12-18",0.18148,{"date":279,"score":183,"percentile":280},"2025-12-19",0.1816,{"date":282,"score":183,"percentile":283},"2025-12-20",0.18143,{"date":285,"score":183,"percentile":286},"2025-12-21",0.18085,{"date":288,"score":183,"percentile":289},"2025-12-22",0.18039,{"date":291,"score":183,"percentile":292},"2025-12-23",0.18044,{"date":294,"score":295,"percentile":296},"2025-12-24",0.00014,0.01906,{"date":298,"score":295,"percentile":299},"2025-12-25",0.01912,{"date":301,"score":295,"percentile":299},"2025-12-26",{"date":303,"score":295,"percentile":304},"2025-12-27",0.01891,{"date":306,"score":295,"percentile":307},"2025-12-28",0.01911,{"date":309,"score":295,"percentile":310},"2025-12-29",0.01902,{"date":312,"score":295,"percentile":313},"2025-12-30",0.01895,{"date":315,"score":295,"percentile":316},"2025-12-31",0.01893,{"date":318,"score":295,"percentile":319},"2026-01-01",0.01917,{"date":321,"score":295,"percentile":322},"2026-01-02",0.01909,{"date":324,"score":295,"percentile":325},"2026-01-03",0.01914,{"date":327,"score":295,"percentile":328},"2026-01-04",0.01877,{"date":330,"score":295,"percentile":331},"2026-01-05",0.0188,{"date":333,"score":295,"percentile":334},"2026-01-06",0.01876,{"date":336,"score":295,"percentile":337},"2026-01-07",0.01892,{"date":339,"score":295,"percentile":322},"2026-01-08",{"date":341,"score":295,"percentile":342},"2026-01-09",0.01928,{"date":344,"score":295,"percentile":345},"2026-01-10",0.01941,{"date":347,"score":295,"percentile":348},"2026-01-11",0.0193,{"date":350,"score":295,"percentile":351},"2026-01-12",0.01932,{"date":353,"score":295,"percentile":354},"2026-01-13",0.01924,{"date":356,"score":295,"percentile":351},"2026-01-14",{"date":358,"score":295,"percentile":359},"2026-01-15",0.01926,{"date":361,"score":295,"percentile":359},"2026-01-16",{"date":363,"score":295,"percentile":364},"2026-01-17",0.01929,{"date":366,"score":295,"percentile":345},"2026-01-18",{"date":368,"score":295,"percentile":369},"2026-01-19",0.01931,{"date":371,"score":295,"percentile":372},"2026-01-20",0.01915,{"date":374,"score":295,"percentile":375},"2026-01-21",0.0191,{"date":377,"score":295,"percentile":378},"2026-01-22",0.01905,{"date":380,"score":295,"percentile":381},"2026-01-23",0.01913,{"date":383,"score":295,"percentile":354},"2026-01-24",{"date":385,"score":295,"percentile":319},"2026-01-25",{"date":387,"score":295,"percentile":372},"2026-01-26",{"date":389,"score":295,"percentile":307},"2026-01-27",{"date":391,"score":295,"percentile":381},"2026-01-28",{"date":393,"score":295,"percentile":369},"2026-01-29",{"date":395,"score":295,"percentile":396},"2026-01-30",0.01933,{"date":398,"score":295,"percentile":399},"2026-01-31",0.01954,{"date":401,"score":295,"percentile":402},"2026-02-01",0.01983,[404,409],{"source":97,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":405,"cvss_v4_0":9},{"baseScore":95,"baseSeverity":406,"vectorString":98,"impactScore":407,"exploitabilityScore":408},"HIGH",9.8,7.2,{"source":103,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":410,"cvss_v4_0":9},{"baseScore":411,"baseSeverity":412,"vectorString":413,"impactScore":414,"exploitabilityScore":415},5.5,"MEDIUM","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",6,4.6,[417,426,455],{"ecosystem":9,"name":418,"vendor":419,"product":420,"cpe_part":421,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":422},"debian linux","debian","debian_linux","o",[423],{"version":424,"is_range":91,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"10.0","cpe",{"ecosystem":9,"name":427,"vendor":428,"product":428,"cpe_part":429,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":430},"Linux","linux","a",[431,438,441,444,447,450,453],{"version":432,"is_range":433,"range_type":97,"version_start":434,"version_start_type":435,"version_end":436,"version_end_type":437,"fixed_in":9},">= 9fd1ff5d2ac7181844735806b0a703c942365291, \u003C 3391b157780bbedf8ef9f202cbf10ee90bf6b0f8",true,"9fd1ff5d2ac7181844735806b0a703c942365291","including","3391b157780bbedf8ef9f202cbf10ee90bf6b0f8","excluding",{"version":439,"is_range":433,"range_type":97,"version_start":434,"version_start_type":435,"version_end":440,"version_end_type":437,"fixed_in":9},">= 9fd1ff5d2ac7181844735806b0a703c942365291, \u003C d49ae15a5767d4e9ef8bbb79e42df1bfebc94670","d49ae15a5767d4e9ef8bbb79e42df1bfebc94670",{"version":442,"is_range":433,"range_type":97,"version_start":434,"version_start_type":435,"version_end":443,"version_end_type":437,"fixed_in":9},">= 9fd1ff5d2ac7181844735806b0a703c942365291, \u003C d12245080cb259d82b34699f6cd4ec11bdb688bd","d12245080cb259d82b34699f6cd4ec11bdb688bd",{"version":445,"is_range":433,"range_type":97,"version_start":434,"version_start_type":435,"version_end":446,"version_end_type":437,"fixed_in":9},">= 9fd1ff5d2ac7181844735806b0a703c942365291, \u003C 3001e7aa43d6691db2a878b0745b854bf12ddd19","3001e7aa43d6691db2a878b0745b854bf12ddd19",{"version":448,"is_range":433,"range_type":97,"version_start":434,"version_start_type":435,"version_end":449,"version_end_type":437,"fixed_in":9},">= 9fd1ff5d2ac7181844735806b0a703c942365291, \u003C 35fe0e0b5c00bef7dde74842a2564c43856fbce4","35fe0e0b5c00bef7dde74842a2564c43856fbce4",{"version":451,"is_range":433,"range_type":97,"version_start":434,"version_start_type":435,"version_end":452,"version_end_type":437,"fixed_in":9},">= 9fd1ff5d2ac7181844735806b0a703c942365291, \u003C 3d010c8031e39f5fa1e8b13ada77e0321091011f","3d010c8031e39f5fa1e8b13ada77e0321091011f",{"version":454,"is_range":91,"range_type":97,"version_start":454,"version_start_type":435,"version_end":454,"version_end_type":435,"fixed_in":9},"5.6",{"ecosystem":9,"name":456,"vendor":428,"product":457,"cpe_part":421,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":458},"linux kernel","linux_kernel",[459,462,466,470,474,478,480],{"version":460,"is_range":433,"range_type":425,"version_start":454,"version_start_type":435,"version_end":461,"version_end_type":437,"fixed_in":9},"gte5.6_lt5.10.215","5.10.215",{"version":463,"is_range":433,"range_type":425,"version_start":464,"version_start_type":435,"version_end":465,"version_end_type":437,"fixed_in":9},"gte5.11_lt5.15.154","5.11","5.15.154",{"version":467,"is_range":433,"range_type":425,"version_start":468,"version_start_type":435,"version_end":469,"version_end_type":437,"fixed_in":9},"gte5.16_lt6.1.85","5.16","6.1.85",{"version":471,"is_range":433,"range_type":425,"version_start":472,"version_start_type":435,"version_end":473,"version_end_type":437,"fixed_in":9},"gte6.2_lt6.6.26","6.2","6.6.26",{"version":475,"is_range":433,"range_type":425,"version_start":476,"version_start_type":435,"version_end":477,"version_end_type":437,"fixed_in":9},"gte6.7_lt6.8.5","6.7","6.8.5",{"version":479,"is_range":91,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.9:rc1",{"version":481,"is_range":91,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.9:rc2"]