Answer in brief
CVE-2024-41091 records a Unknown severity vulnerability in tun: add missing verification for short frame. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2024-41091 records a Unknown severity vulnerability in tun: add missing verification for short frame. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=043d222f93ab8c76b56a3b315cd8692e35affb6c <32b0aaba5dbc85816898167d9b5d45a22eae82e9 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <6100e0237204890269e3f934acfc50d35fd6f319 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <d5ad89b7d01ed4e66fd04734fc63d6e78536692a || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <8418f55302fa1d2eeb73e16e345167e545c598a5 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <049584807f1d797fc3078b68035450a9769eb5c3 | 32b0aaba5dbc85816898167d9b5d45a22eae82e9, 6100e0237204890269e3f934acfc50d35fd6f319, 589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2, ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146, d5ad89b7d01ed4e66fd04734fc63d6e78536692a, a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb, 8418f55302fa1d2eeb73e16e345167e545c598a5, 049584807f1d797fc3078b68035450a9769eb5c3 |
| Linux/Linuxgeneric | 4.20 | Not reported |
Published upstream
Jul 29, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tun_xdp_one() path, which could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tun_xdp_one-->eth_type_trans() may access the Ethernet header although it can be less than ETH_HLEN. Once transmitted, this could either cause out-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata. In the alternative path, tun_get_user() already prohibits short frame which has the length less than Ethernet header size from being transmitted for IFF_TAP. This is to drop any frame shorter than the Ethernet header size just like how tun_get_user() does. CVE: CVE-2024-41091
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=043d222f93ab8c76b56a3b315cd8692e35affb6c <32b0aaba5dbc85816898167d9b5d45a22eae82e9 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <6100e0237204890269e3f934acfc50d35fd6f319 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <d5ad89b7d01ed4e66fd04734fc63d6e78536692a || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <8418f55302fa1d2eeb73e16e345167e545c598a5 || >=043d222f93ab8c76b56a3b315cd8692e35affb6c <049584807f1d797fc3078b68035450a9769eb5c3 | 32b0aaba5dbc85816898167d9b5d45a22eae82e9, 6100e0237204890269e3f934acfc50d35fd6f319, 589382f50b4a5d90d16d8bc9dcbc0e927a3e39b2, ad6b3f622ccfb4bfedfa53b6ebd91c3d1d04f146, d5ad89b7d01ed4e66fd04734fc63d6e78536692a, a9d1c27e2ee3b0ea5d40c105d6e728fc114470bb, 8418f55302fa1d2eeb73e16e345167e545c598a5, 049584807f1d797fc3078b68035450a9769eb5c3 |
| Linux/Linuxgeneric | 4.20 | Not reported |
Published upstream
Jul 29, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The cited commit missed to check against the validity of the frame length in the tun_xdp_one() path, which could cause a corrupted skb to be sent downstack. Even before the skb is transmitted, the tun_xdp_one-->eth_type_trans() may access the Ethernet header although it can be less than ETH_HLEN. Once transmitted, this could either cause out-of-bound access beyond the actual length, or confuse the underlayer with incorrect or inconsistent header length in the skb metadata. In the alternative path, tun_get_user() already prohibits short frame which has the length less than Ethernet header size from being transmitted for IFF_TAP. This is to drop any frame shorter than the Ethernet header size just like how tun_get_user() does. CVE: CVE-2024-41091
Quoted source text, attributed separately from HOL analysis.