CVE-2024-41048: skmsg: Skip zero length skb in sk_msg_recvmsg
In the Linux kernel, the following vulnerability has been resolved:
skmsg: Skip zero length skb in sk_msg_recvmsg
When running BPF selftests (./test_progs -t sockmap_basic) on a Loongarch
platform, the following kernel panic occurs:
[...]
Oops[#1]:
CPU: 22 PID: 2824 Comm: test_progs Tainted: G OE 6.10.0-rc2+ #18
Hardware name: LOONGSON Dabieshan/Loongson-TC542F0, BIOS Loongson-UDK2018
... ...
ra: 90000000048bf6c0 sk_msg_recvmsg+0x120/0x560
ERA: 9000000004162774 copy_page_to_iter+0x74/0x1c0
CRMD: 000000b0 (PLV0 -IE -DA +PG DACF=CC DACM=CC -WE)
PRMD: 0000000c (PPLV0 +PIE +PWE)
EUEN: 00000007 (+FPE +SXE +ASXE -BTE)
ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)
ESTAT: 00010000 [PIL] (IS= ECode=1 EsubCode=0)
BADV: 0000000000000040
PRID: 0014c011 (Loongson-64bit, Loongson-3C5000)
Modules linked in: bpf_testmod(OE) xt_CHECKSUM xt_MASQUERADE xt_conntrack
Process test_progs (pid: 2824, threadinfo=0000000000863a31, task=...)
Stack : ...
Call Trace:
[<9000000004162774>] copy_page_to_iter+0x74/0x1c0
[<90000000048bf6c0>] sk_msg_recvmsg+0x120/0x560
[<90000000049f2b90>] tcp_bpf_recvmsg_parser+0x170/0x4e0
[<90000000049aae34>] inet_recvmsg+0x54/0x100
[<900000000481ad5c>] sock_recvmsg+0x7c/0xe0
[<900000000481e1a8>] __sys_recvfrom+0x108/0x1c0
[<900000000481e27c>] sys_recvfrom+0x1c/0x40
[<9000000004c076ec>] do_syscall+0x8c/0xc0
[<9000000003731da4>] handle_syscall+0xc4/0x160
Code: ...
---[ end trace 0000000000000000 ]---
Kernel panic - not syncing: Fatal exception
Kernel relocated by 0x3510000
.text @ 0x9000000003710000
.data @ 0x9000000004d70000
.bss @ 0x9000000006469400
---[ end Kernel panic - not syncing: Fatal exception ]---
[...]
This crash happens every time when running sockmap_skb_verdict_shutdown
subtest in sockmap_basic.
This crash is because a NULL pointer is passed to page_address() in the
sk_msg_recvmsg(). Due to the different implementations depending on the
architecture, page_address(NULL) will trigger a panic on Loongarch
platform but not on x86 platform. So this bug was hidden on x86 platform
for a while, but now it is exposed on Loongarch platform. The root cause
is that a zero length skb (skb->len == 0) was put on the queue.
This zero length skb is a TCP FIN packet, which was sent by shutdown(),
invoked in test_sockmap_skb_verdict_shutdown():
shutdown(p1, SHUT_WR);
In this case, in sk_psock_skb_ingress_enqueue(), num_sge is zero, and no
page is put to this sge (see sg_set_page in sg_set_page), but this empty
sge is queued into ingress_msg list.
And in sk_msg_recvmsg(), this empty sge is used, and a NULL page is got by
sg_page(sge). Pass this NULL page to copy_page_to_iter(), which passes it
to kmap_local_page() and to page_address(), then kernel panics.
To solve this, we should skip this zero length skb. So in sk_msg_recvmsg(),
if copy is zero, that means it's a zero length skb, skip invoking
copy_page_to_iter(). We are using the EFAULT return triggered by
copy_page_to_iter to check for is_fin in tcp_bpf.c.
Security readout for executives and security teams
Plain-English summary
A zero-length TCP FIN queued through Linux BPF sockmap handling can lead the kernel to dereference a null page and panic. The failure was consistently reproduced on LoongArch, causing system unavailability. Other architectures may conceal the same underlying defect rather than crash.
Executive priority
Treat as a high-priority availability issue where affected kernels and BPF sockmap usage overlap, particularly on LoongArch. Schedule vendor-supported kernel updates promptly. Broader emergency action is not supported by the supplied exploitation evidence.
Technical view
The sockmap ingress path can queue an empty scatter-gather entry when processing a zero-length FIN. sk_msg_recvmsg then passes its null page into the copy path, triggering a LoongArch kernel panic. The stable fixes skip copy_page_to_iter when the calculated copy length is zero.
Likely exposure
Exposure is most credible on affected Linux kernels using BPF sockmap functionality, especially LoongArch systems. The supplied record lists affected releases across multiple kernel branches. Architecture-specific behavior may prevent an obvious x86 crash, but does not establish that the underlying condition is absent.
Exploitation context
The CVSS record rates this as network-accessible, low complexity, unauthenticated, and availability-only. However, the supplied evidence demonstrates a repeatable BPF selftest crash, not a real-world remote attack. The CVE is not listed as KEV, and the bundle provides no evidence of active exploitation.
Researcher notes
The reported trigger is an empty ingress scatter-gather entry created from a FIN generated by shutdown. LoongArch page_address(NULL) exposes the defect as a panic, while x86 behavior reportedly hid it. Source evidence does not establish confidentiality impact, integrity impact, exploitation in the wild, or universal reachability from an untrusted network.
Mitigation direction
Install a vendor kernel update containing the applicable Linux stable fix commit.
Review Linux distribution advisories to identify the corrected package for each deployed kernel branch.
Prioritize affected LoongArch systems and workloads that use BPF sockmap functionality.
Validation and detection
Inventory deployed kernel versions, architectures, and workloads using BPF sockmap features.
Confirm the installed kernel package includes the applicable stable fix or vendor backport.
Run the relevant sockmap regression test only in a controlled, non-production environment.
Monitor affected systems for kernel panics involving sk_msg_recvmsg or copy_page_to_iter.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-41048 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.