{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2024-57791",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-01-09T09:50:31.752Z",
        "datePublished": "2025-01-11T12:35:48.905Z",
        "dateUpdated": "2026-08-05T11:46:31.003Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:46:31.003Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: check return value of sock_recvmsg when draining clc data\n\nWhen receiving clc msg, the field length in smc_clc_msg_hdr indicates the\nlength of msg should be received from network and the value should not be\nfully trusted as it is from the network. Once the value of length exceeds\nthe value of buflen in function smc_clc_wait_msg it may run into deadloop\nwhen trying to drain the remaining data exceeding buflen.\n\nThis patch checks the return value of sock_recvmsg when draining data in\ncase of deadloop in draining."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - SMC CLC handshake messages arrive over routable TCP/IP; the malicious `hdr.length` and the subsequent FIN/RST come entirely from a remote peer connecting to an SMC listener (or from a malicious server a client connects to). No adjacency requirement.\nAC:L - The attacker deterministically triggers the loop by sending a V2 CLC ACCEPT/CONFIRM/DECLINE header whose length field exceeds the receive buffer and then closing the socket; there is no race, no memory-layout dependency, and every input is attacker-controlled.\nPR:N - The CLC exchange is the very first thing processed after the TCP handshake and SMC performs no authentication whatsoever, so an unauthenticated remote peer reaches `smc_clc_wait_msg()` directly.\nUI:N - On the server side `smc_listen_work()` processes the crafted message automatically on connection acceptance; no local user action is needed.\nS:U - The hang is confined to the kernel's own security authority — a stuck workqueue worker/task and an SMC mutex; no boundary such as a VM or IOMMU domain is crossed.\nC:N - The drain loop reads into a bounded 100-byte stack buffer whose kvec `iov_len` caps every copy, and the discarded data is never returned to anyone; no memory contents are disclosed.\nI:N - No out-of-bounds write or state corruption occurs — even when `datlen` wraps negative, the kvec length bound prevents any overflow, so no data is modified.\nA:H - The unkillable infinite loop burns 100% of a CPU per connection while holding `lock_sock()` and, for SMC-R, the global `smc_server_lgr_pending` mutex, permanently wedging all SMC handshakes on the host; repeating it across connections exhausts every CPU and handshake worker."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/smc/smc_clc.c"
                    ],
                    "versions": [
                        {
                            "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
                            "lessThan": "82c7ad9ca09975aae737abffd66d1ad98874c13d",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
                            "lessThan": "6b80924af6216277892d5f091f5bfc7d1265fa28",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
                            "lessThan": "d7d1f986ebb284b1db8dafca7d1bdb6dd2445cf6",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
                            "lessThan": "7a6927814b4256d603e202ae7c5e38db3b338896",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
                            "lessThan": "df3dfe1a93c6298d8c09a18e4fba19ef5b17763b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "fb4f79264c0fc6fd5a68ffe3e31bfff97311e1f1",
                            "lessThan": "c5b8ee5022a19464783058dc6042e8eefa34e8cd",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/smc/smc_clc.c"
                    ],
                    "versions": [
                        {
                            "version": "5.8",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.8",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.233",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.176",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.122",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.68",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.7",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.8",
                                    "versionEndExcluding": "5.10.233"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.8",
                                    "versionEndExcluding": "5.15.176"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.8",
                                    "versionEndExcluding": "6.1.122"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.8",
                                    "versionEndExcluding": "6.6.68"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.8",
                                    "versionEndExcluding": "6.12.7"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.8",
                                    "versionEndExcluding": "6.13"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/82c7ad9ca09975aae737abffd66d1ad98874c13d"
                },
                {
                    "url": "https://git.kernel.org/stable/c/6b80924af6216277892d5f091f5bfc7d1265fa28"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d7d1f986ebb284b1db8dafca7d1bdb6dd2445cf6"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7a6927814b4256d603e202ae7c5e38db3b338896"
                },
                {
                    "url": "https://git.kernel.org/stable/c/df3dfe1a93c6298d8c09a18e4fba19ef5b17763b"
                },
                {
                    "url": "https://git.kernel.org/stable/c/c5b8ee5022a19464783058dc6042e8eefa34e8cd"
                }
            ],
            "title": "net/smc: check return value of sock_recvmsg when draining clc data",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
                    },
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T20:54:28.243Z"
                }
            }
        ]
    }
}