Back

HIGH

xsk: fix an integer overflow in xp_create_and_assign_umem()

Published Apr 3, 2025

Description

Since the i and pool->chunk_size variables are of type 'u32', their product can wrap around and then be cast to 'u64'. This can lead to two different XDP buffers pointing to the same memory area.

Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Apr 3, 2025
Updated May 11, 2026
Reserved Dec 29, 2024
CISA Vulnrichment
Updated Oct 1, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 3, 2025