{"id":"CVE-2024-57973","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nrdma/cxgb4: Prevent potential integer overflow on 32bit\n\nThe \"gl->tot_len\" variable is controlled by the user","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nrdma/cxgb4: Prevent potential integer overflow on 32bit\n\nThe \"gl->tot_len\" variable is controlled by the user.  It comes from\nprocess_responses().  On 32bit systems, th…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-190"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 3.8, < 6.1.129","linux_kernel >= 6.2, < 6.6.76","linux_kernel >= 6.7, < 6.12.13","linux_kernel >= 6.13, < 6.13.2"],"patched":["linux_kernel 6.13.2"],"published":"2025-02-27","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-57973","references":[{"url":"https://git.kernel.org/stable/c/2b759f78b83221f4a1cae3aeb20b500e375f3ee6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/4422f452d028850b9cc4fd8f1cf45a8ff91855eb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aeb814484387811b3579d5c78ad4eb301e3bf1c8","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/bd96a3935e89486304461a21752f824fc25e0f0b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d64148a10a85952352de6091ceed99fb9ce2d3ee","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dd352107f22bfbecbbf3b74bde14f3f932296309","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/de8d88b68d0cfd41152a7a63d6aec0ed3e1b837a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e53ca458f543aa352d09b484550de173cb9085c2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd","cve.org"],"epss":0.00666,"epssPercentile":0.50382,"ingestedAt":"2026-07-14T13:36:55.041Z","slug":"CVE-2024-57973","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nrdma/cxgb4: Prevent potential integer overflow on 32bit\n\nThe \"gl->tot_len\" variable is controlled by the user.  It comes from\nprocess_responses().  On 32bit systems, the \"gl->tot_len + sizeof(struct\ncpl_pass_accept_req) + sizeof(struct rss_header)\" addition could have an\ninteger wrapping bug.  Use size_add() to prevent this.\n\n## Affected\n\n- `linux_kernel >= 3.8, < 6.1.129`\n- `linux_kernel >= 6.2, < 6.6.76`\n- `linux_kernel >= 6.7, < 6.12.13`\n- `linux_kernel >= 6.13, < 6.13.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.13.2`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}