Executive brief
The Linux kernel's ARM64 architecture contains a vulnerability in the IP checksum calculation code that can be triggered by negative input lengths. An attacker can exploit this to read memory outside allocated buffers, potentially exposing sensitive kernel data or causing denial of service. This vulnerability affects systems running vulnerable Linux kernels on ARM64 processors.
Technical details
The vulnerability is an out-of-bounds (OoB) read in the do_csum function in arch/arm64/lib/csum.c caused by insufficient input validation. The code previously added protection against zero-length input but did not check for negative lengths, which triggers undefined shift behavior and reading beyond buffer boundaries. The attack vector is network-based, as the vulnerability can be triggered via malformed network packets processed through UDP GSO (Generic Segmentation Offload) operations, requiring no authentication. An attacker can read up to 4GB of adjacent kernel memory. The fix extends the early return validation to reject both zero-length and negative-length inputs, aligning with the generic checksum implementation.
Affected products
- Linux Linux kernel up to and including 6.4.0-rc4
Timeline
- 2025-10-22: disclosed: CVE-2023-53726 published