{"id":"DEBIAN-CVE-2024-58099","details":"In the Linux kernel, the following vulnerability has been resolved:  vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame  Andrew and Nikolay reported connectivity issues with Cilium's service load-balancing in case of vmxnet3.  If a BPF program for native XDP adds an encapsulation header such as IPIP and transmits the packet out the same interface, then in case of vmxnet3 a corrupted packet is being sent and subsequently dropped on the path.  vmxnet3_xdp_xmit_frame() which is called e.g. via vmxnet3_run_xdp() through vmxnet3_xdp_xmit_back() calculates an incorrect DMA address:    page = virt_to_page(xdpf-\u003edata);   tbi-\u003edma_addr = page_pool_get_dma_addr(page) +                   VMXNET3_XDP_HEADROOM;   dma_sync_single_for_device(&adapter-\u003epdev-\u003edev,                              tbi-\u003edma_addr, buf_size,                              DMA_TO_DEVICE);  The above assumes a fixed offset (VMXNET3_XDP_HEADROOM), but the XDP BPF program could have moved xdp-\u003edata. While the passed buf_size is correct (xdpf-\u003elen), the dma_addr needs to have a dynamic offset which can be calculated as xdpf-\u003edata - (void *)xdpf, that is, xdp-\u003edata - xdp-\u003edata_hard_start.","modified":"2026-09-15T09:03:18.159564724Z","published":"2025-04-29T12:15:31.053Z","upstream":["CVE-2024-58099"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-58099"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-58099.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.11.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-58099.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}