tcp: avoid too many retransmit packets
Published Jul 15, 2024
7.5
HIGHCVSS 3.1
EPSS 0.77%
Description
If a TCP socket is using TCP_USER_TIMEOUT, and the other peer retracted its window to zero, tcp_retransmit_timer() can retransmit a packet every two jiffies (2 ms for HZ=1000), for about 4 minutes after TCP_USER_TIMEOUT has 'expired'.
The fix is to make sure tcp_rtx_probe0_timed_out() takes icsk->icsk_user_timeout into account.
Before blamed commit, the socket would not timeout after icsk->icsk_user_timeout, but would use standard exponential backoff for the retransmits.
Also worth noting that before commit e89688e3e978 ("net: tcp: fix unexcepted socket die when snd_wnd is 0"), the issue would last 2 minutes instead of 4.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.19
- Version 4.19.318StatusunaffectedConstraints<=4.19.*
- Version 5.10.222StatusunaffectedConstraints<=5.10.*
- Version 5.15.163StatusunaffectedConstraints<=5.15.*
- Version 5.4.280StatusunaffectedConstraints<=5.4.*
- Version 6.1.100StatusunaffectedConstraints<=6.1.*
- Version 6.10StatusunaffectedConstraints<=*
- Version 6.6.41StatusunaffectedConstraints<=6.6.*
- Version 6.9.10StatusunaffectedConstraints<=6.9.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.19 · < 5.4.280
- ≥ 5.5 · < 5.10.222
- ≥ 5.11 · < 5.15.163
- ≥ 5.16 · < 6.1.100
- ≥ 6.2 · < 6.6.41
- ≥ 6.7 · < 6.9.10
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-553.22.1.el8_10
Fixed · RHSA-2024:7000
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10
Fixed · RHSA-2024:7001
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9
kernel-0:5.14.0-503.11.1.el9_5
Fixed · RHSA-2024:9315
Red Hat Enterprise Linux 9.4 Extended Update Support
kernel-0:5.14.0-427.47.1.el9_4
Fixed · RHSA-2024:10771
Red Hat Enterprise Linux 6
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-553.22.1.el8_10 | Fixed | RHSA-2024:7000 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-553.22.1.rt7.363.el8_10 | Fixed | RHSA-2024:7001 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-503.11.1.el9_5 | Fixed | RHSA-2024:9315 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | kernel-0:5.14.0-427.47.1.el9_4 | Fixed | RHSA-2024:10771 |
| Red Hat Enterprise Linux 6 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
2 other sources (CVE.org, Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 10, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (6 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.77% (0.00773) | 54.08th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.23% (0.00229) | 13.43th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00072) | 19.34th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 14.69th | v3 (v2023.03.01) |
| Jul 19, 2024 | 0.04% (0.00044) | 13.43th | v3 (v2023.03.01) |
| Jul 16, 2024 | 0.04% (0.00043) | 9.28th | v3 (v2023.03.01) |
References (14)
- https://access.redhat.com/security/cve/CVE-2024-41007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2297909 Issue Tracking
- https://git.kernel.org/stable/c/04317a2471c2f637b4c49cbd0e9c0d04a519f570 Patch
- https://git.kernel.org/stable/c/5d7e64d70a11d988553a08239c810a658e841982 Patch
- https://git.kernel.org/stable/c/66cb64a1d2239cd0309f9b5038b05462570a5be1 Patch
- https://git.kernel.org/stable/c/7bb7670f92bfbd05fc41a8f9a8f358b7ffed65f4 Patch
- https://git.kernel.org/stable/c/97a9063518f198ec0adb2ecb89789de342bb8283 Patch
- https://git.kernel.org/stable/c/d2346fca5bed130dc712f276ac63450201d52969 Patch
- https://git.kernel.org/stable/c/dfcdd7f89e401d2c6616be90c76c2fac3fa98fde Patch
- https://git.kernel.org/stable/c/e113cddefa27bbf5a79f72387b8fbd432a61a466 Patch
- https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html
- https://lore.kernel.org/linux-cve-announce/2024071513-CVE-2024-41007-777c@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2024-41007
- https://www.cve.org/CVERecord?id=CVE-2024-41007
Change history (0)
No recorded changes yet.