---
id: CVE-2024-49568
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg

  When receiving proposal msg in server, the fields v2_ext_offset/
  eid_cnt/ism_gid_cnt in pr…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg

  When receiving proposal msg in server, the fields v2_ext_offset/
  eid_cnt/ism_gid_cnt in pr…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.10, < 6.6.68'
  - 'linux_kernel >= 6.7, < 6.12.7'
  - linux_kernel = 6.13
patched:
  - linux_kernel 6.12.7
published: '2025-01-11'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:31.710'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-49568'
references:
  - url: 'https://git.kernel.org/stable/c/295a92e3df32e72aff0f4bc25c310e349d07ffbf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/42f6beb2d5779429417b5f8115a4e3fa695d2a6c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/49798283fce4c1a24fb1ba4c7c39127739535571'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/690b9a8db9460d065785548e43fd6a02d247c1b7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/7863c9f3d24ba49dbead7e03dfbe40deb5888fdf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9cc0170ae646876aa5de2f0cad3066ce53e86f27'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00528
epssPercentile: 0.42676
ingestedAt: '2026-10-03T11:43:42.105Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg

When receiving proposal msg in server, the fields v2_ext_offset/
eid_cnt/ism_gid_cnt in proposal msg are from the remote client
and can not be fully trusted. Especially the field v2_ext_offset,
once exceed the max value, there has the chance to access wrong
address, and crash may happen.

This patch checks the fields v2_ext_offset/eid_cnt/ism_gid_cnt
before using them.

## Affected

- `linux_kernel >= 5.10, < 6.6.68`
- `linux_kernel >= 6.7, < 6.12.7`
- `linux_kernel = 6.13`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.12.7`
