{"id":"DEBIAN-CVE-2024-35944","details":"In the Linux kernel, the following vulnerability has been resolved:  VMCI: Fix memcpy() run-time warning in dg_dispatch_as_host()  Syzkaller hit 'WARNING in dg_dispatch_as_host' bug.  memcpy: detected field-spanning write (size 56) of single field \"&dg_info-\u003emsg\" at drivers/misc/vmw_vmci/vmci_datagram.c:237 (size 24)  WARNING: CPU: 0 PID: 1555 at drivers/misc/vmw_vmci/vmci_datagram.c:237 dg_dispatch_as_host+0x88e/0xa60 drivers/misc/vmw_vmci/vmci_datagram.c:237  Some code commentry, based on my understanding:  544 #define VMCI_DG_SIZE(_dg) (VMCI_DG_HEADERSIZE + (size_t)(_dg)-\u003epayload_size) /// This is 24 + payload_size  memcpy(&dg_info-\u003emsg, dg, dg_size); \tDestination = dg_info-\u003emsg ---\u003e this is a 24 byte \t\t\t\t\tstructure(struct vmci_datagram) \tSource = dg --\u003e this is a 24 byte structure (struct vmci_datagram) \tSize = dg_size = 24 + payload_size  {payload_size = 56-24 =32} -- Syzkaller managed to set payload_size to 32.   35 struct delayed_datagram_info {  36         struct datagram_entry *entry;  37         struct work_struct work;  38         bool in_dg_host_queue;  39         /* msg and msg_payload must be together. */  40         struct vmci_datagram msg;  41         u8 msg_payload[];  42 };  So those extra bytes of payload are copied into msg_payload[], a run time warning is seen while fuzzing with Syzkaller.  One possible way to fix the warning is to split the memcpy() into two parts -- one -- direct assignment of msg and second taking care of payload.  Gustavo quoted: \"Under FORTIFY_SOURCE we should not copy data across multiple members in a structure.\"","modified":"2026-09-15T09:03:05.703147949Z","published":"2024-05-19T11:15:50.017Z","upstream":["CVE-2024-35944"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-35944"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.90-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-35944.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-35944.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.9-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-35944.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}