CVE-2024-57843 is a memory overflow in the Linux kernel virtio-net driver that can silently corrupt memory on a running instance. This topic describes which Alibaba Cloud ECS official Linux images are affected, how to determine whether an instance is affected, and how to fix an affected instance.
Vulnerability overview
CVE-2024-57843 is a memory overflow defect in the virtio-net driver of the Linux kernel that occurs when the driver fills mergeable RX buffers. The defect was introduced by upstream commit 295525e29a5b (virtio_net: merge dma operations when filling mergeable buffers) and fixed by commit 6aacd1484468 (virtio-net: fix overflow inside virtnet_rq_alloc).
Red Hat rates this vulnerability as Moderate, and Ubuntu rates it as Medium.
Symptoms
An affected ECS instance may show the following symptoms:
Unexpected instance crash — The instance crashes without warning (kernel panic), and the dmesg log contains entries related to
general protection faultorpagealloc: memory corruption.Large file transfer failure — A transfer of a file of about 100 MB or larger over scp is interrupted.
Silent corruption of kernel data structures — Page table pages, slab objects,
buffer_headstructures, and similar data are unexpectedly overwritten, which leads to unpredictable system behavior.
Affected scope
The following table lists the ECS official Linux images evaluated for CVE-2024-57843, why each distribution is affected, and the fix status of the corresponding ECS images.
| Distribution | Affected version | Cause | Fix status of ECS images |
| Ubuntu | 24.04 LTS | Affected from the first release, because the 6.8 kernel baseline includes the defect-introducing patch that was backported to 6.6. Fixed in 6.8.0-58.60. | Images released in May 2025 are fixed (6.8.0-60-generic). |
| CentOS Stream 9 | 9 | Follows RHEL upstream. Fixed in 5.14.0-570.12.1.el9_6. | The patched images released in March 2025 are fixed. |
| Fedora | 40 (EOL) | Introduced in kernel-6.6.2-201.fc40. Fixed in 6.12.5-200. | Reached EOL. No update is planned. |
Check whether your instance is affected
The running kernel version determines whether an ECS instance contains the defect. Run the following command on the instance to get the running kernel version:
uname -rCompare the output with the fix version listed for your distribution in the affected scope table:
Earlier than the fix version — The instance is affected. Upgrade the kernel and restart the instance.
The fix version or later — The running kernel contains the fix, and no further action is required.
The trigger conditions described in the root cause section determine whether the defect is triggered at runtime. They do not determine whether the running kernel contains the defect, so use the kernel version as the decision criterion.
Fix an affected instance
For all distributions, the fix requires you to upgrade the kernel packages and restart the instance before the fix takes effect.
Restarting the instance interrupts every service running on it. Plan the restart before you upgrade the kernel.
Ubuntu 24.04 LTS
Upgrade the kernel to 6.8.0-58-generic (package version 6.8.0-58.60) or later.
Confirm that a qualifying kernel version is available. The following commands refresh the package index and list the
linux-image-genericversions offered by your configured repositories.sudo apt update apt-cache madison linux-image-genericUpgrade the kernel packages.
sudo apt install -y --only-upgrade linux-image-genericRestart the instance.
sudo rebootAfter the restart, confirm the running kernel version.
uname -rVerify that the output is
6.8.0-58-genericor later.
Ubuntu reports the same kernel as 6.8.0-58-generic in uname -r output and as 6.8.0-58.60 in package metadata. The 6.8.0-60-generic kernel shipped in ECS images released in May 2025 is later than 6.8.0-58-generic and therefore contains the fix.
CentOS Stream 9
Upgrade the kernel to kernel-5.14.0-570.12.1.el9_6 or later.
Upgrade the kernel packages.
sudo dnf clean all && sudo dnf makecache sudo dnf -y update kernelRestart the instance.
sudo rebootAfter the restart, confirm the running kernel version.
uname -rVerify that the output is
5.14.0-570.12.1.el9_6or later.
Fedora 40 (EOL)
Fedora 40 has reached EOL and is no longer maintained, and no update is planned for the ECS official Fedora 40 images. Upgrade to Fedora 41 or later.
If you continue to run Fedora 40, upgrade the kernel to 6.12.5-200 or later.
Upgrade the kernel packages.
sudo dnf clean all && sudo dnf makecache sudo dnf -y update kernelRestart the instance.
sudo rebootAfter the restart, confirm the running kernel version.
uname -rVerify that the output is
6.12.5-200or later.
Temporary mitigation
No temporary mitigation is available for CVE-2024-57843. Upgrade to a kernel version that contains the fix. Changing any of the trigger conditions described in the root cause section is not a substitute for the kernel upgrade.
Do not set net.core.high_order_alloc_disable=1 in production environments. On kernel versions that contain the vulnerability, this parameter significantly increases the probability that the vulnerability is triggered. Kernel versions without the vulnerability are not affected.
Root cause
CVE-2024-57843 is a 16-byte cross-page overflow that occurs when the virtio-net driver fills mergeable RX buffers with data.
In premapped DMA mode (do_dma=true), each frag page must reserve 16 bytes at the start of the page to store mapping information. When all of the conditions in the following table are met, the driver allocates a 4096-byte (order-0) page but must write 16 + 4096 = 4112 bytes. The last 16 bytes are written to the physically adjacent next page, which silently corrupts memory.
| No. | Trigger condition | Description |
| 1 | premapped DMA is active | 16 bytes must be reserved at the start of the page. |
| 2 | mergeable RX buffers are used and XDP is disabled | Determines the code path that calculates the buffer length. |
| 3 | MTU >= 4084 and the EWMA of the traffic packet length > 4020 | Saturates len to 4096. |
| 4 | The frag page falls back from order-3 to order-0 (transient memory pressure) | An order-3 page (32 KB) has enough space, but an order-0 page (4 KB) does not. |
Prevent new instances from being affected
When you create an ECS instance, use an official image that already contains the fix.
If crashes persist after the upgrade
If similar crashes still occur after you upgrade the kernel, collect the vmcore file and submit a ticket for troubleshooting assistance.