Impact
A user can craft a packet with an AF_PACKET PACKET_VNET_HDR socket, setting the gso_size field to any value, even below the required minimum of 8 bytes. The virtio-net driver in the Linux kernel divides the socket buffer length by this gso_size and stores the result in a 16‑bit gso_segs field. When gso_size is less than 8, the division can produce a value larger than 65535, causing the 16‑bit field to overflow and corrupt memory. This overflow can destabilize the kernel and lead to a crash or other malicious behavior such as memory corruption. The vulnerability exists only in the virtio‑net driver and is triggered by malformed TCP packets with an invalid gso_size.
Affected Systems
All Linux kernel versions prior to the commit that validates gso_size in virtio‑net are affected. The issue arises wherever virtio‑net networking is enabled, which is common in virtual machines that use VirtIO devices. Any kernel lacking the fix that enforces a minimum TCP gso_size of 8 is vulnerable; the exact version range is not listed in the data, but the vulnerability affects all kernels before the patch.
Risk and Exploitability
The EPSS score indicates a very low probability of exploitation (<1%). The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker needs to create an AF_PACKET PACKET_VNET_HDR socket, which typically requires CAP_NET_RAW or root privileges. Thus the exploitation is likely local rather than remote, and the impact would be memory corruption leading to a kernel crash or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA