{"id":"DEBIAN-CVE-2024-27013","details":"In the Linux kernel, the following vulnerability has been resolved:  tun: limit printing rate when illegal packet received by tun dev  vhost_worker will call tun call backs to receive packets. If too many illegal packets arrives, tun_do_read will keep dumping packet contents. When console is enabled, it will costs much more cpu time to dump packet and soft lockup will be detected.  net_ratelimit mechanism can be used to limit the dumping rate.  PID: 33036    TASK: ffff949da6f20000  CPU: 23   COMMAND: \"vhost-32980\"  #0 [fffffe00003fce50] crash_nmi_callback at ffffffff89249253  #1 [fffffe00003fce58] nmi_handle at ffffffff89225fa3  #2 [fffffe00003fceb0] default_do_nmi at ffffffff8922642e  #3 [fffffe00003fced0] do_nmi at ffffffff8922660d  #4 [fffffe00003fcef0] end_repeat_nmi at ffffffff89c01663     [exception RIP: io_serial_in+20]     RIP: ffffffff89792594  RSP: ffffa655314979e8  RFLAGS: 00000002     RAX: ffffffff89792500  RBX: ffffffff8af428a0  RCX: 0000000000000000     RDX: 00000000000003fd  RSI: 0000000000000005  RDI: ffffffff8af428a0     RBP: 0000000000002710   R8: 0000000000000004   R9: 000000000000000f     R10: 0000000000000000  R11: ffffffff8acbf64f  R12: 0000000000000020     R13: ffffffff8acbf698  R14: 0000000000000058  R15: 0000000000000000     ORIG_RAX: ffffffffffffffff  CS: 0010  SS: 0018  #5 [ffffa655314979e8] io_serial_in at ffffffff89792594  #6 [ffffa655314979e8] wait_for_xmitr at ffffffff89793470  #7 [ffffa65531497a08] serial8250_console_putchar at ffffffff897934f6  #8 [ffffa65531497a20] uart_console_write at ffffffff8978b605  #9 [ffffa65531497a48] serial8250_console_write at ffffffff89796558  #10 [ffffa65531497ac8] console_unlock at ffffffff89316124  #11 [ffffa65531497b10] vprintk_emit at ffffffff89317c07  #12 [ffffa65531497b68] printk at ffffffff89318306  #13 [ffffa65531497bc8] print_hex_dump at ffffffff89650765  #14 [ffffa65531497ca8] tun_do_read at ffffffffc0b06c27 [tun]  #15 [ffffa65531497d38] tun_recvmsg at ffffffffc0b06e34 [tun]  #16 [ffffa65531497d68] handle_rx at ffffffffc0c5d682 [vhost_net]  #17 [ffffa65531497ed0] vhost_worker at ffffffffc0c644dc [vhost]  #18 [ffffa65531497f10] kthread at ffffffff892d2e72  #19 [ffffa65531497f50] ret_from_fork at ffffffff89c0022f","modified":"2026-09-01T20:05:23.810902024Z","published":"2024-05-01T06:15:19.857Z","upstream":["CVE-2024-27013"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-27013"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.90-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-27013.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-27013.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-27013.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}