{"id":"DEBIAN-CVE-2022-49340","details":"In the Linux kernel, the following vulnerability has been resolved:  ip_gre: test csum_start instead of transport header  GRE with TUNNEL_CSUM will apply local checksum offload on CHECKSUM_PARTIAL packets.  ipgre_xmit must validate csum_start after an optional skb_pull, else lco_csum may trigger an overflow. The original check was  \tif (csum && skb_checksum_start(skb) \u003c skb-\u003edata) \t\treturn -EINVAL;  This had false positives when skb_checksum_start is undefined: when ip_summed is not CHECKSUM_PARTIAL. A discussed refinement was straightforward  \tif (csum && skb-\u003eip_summed == CHECKSUM_PARTIAL && \t    skb_checksum_start(skb) \u003c skb-\u003edata) \t\treturn -EINVAL;  But was eventually revised more thoroughly: - restrict the check to the only branch where needed, in an   uncommon GRE path that uses header_ops and calls skb_pull. - test skb_transport_header, which is set along with csum_start   in skb_partial_csum_set in the normal header_ops datapath.  Turns out skbs can arrive in this branch without the transport header set, e.g., through BPF redirection.  Revise the check back to check csum_start directly, and only if CHECKSUM_PARTIAL. Do leave the check in the updated location. Check field regardless of whether TUNNEL_CSUM is configured.","modified":"2026-09-01T16:05:30.570870363Z","published":"2025-02-26T07:01:10.753Z","upstream":["CVE-2022-49340"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-49340"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49340.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49340.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.18.5-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-49340.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}