All Products
Search
Document Center

:Impact scope and fix status of CVE-2024-57843 in ECS official images

Last Updated:Aug 24, 2026

CVE-2024-57843 is a memory overflow in the Linux kernel virtio-net driver that can silently corrupt memory on a running instance. This topic describes which Alibaba Cloud ECS official Linux images are affected, how to determine whether an instance is affected, and how to fix an affected instance.

Vulnerability overview

CVE-2024-57843 is a memory overflow defect in the virtio-net driver of the Linux kernel that occurs when the driver fills mergeable RX buffers. The defect was introduced by upstream commit 295525e29a5b (virtio_net: merge dma operations when filling mergeable buffers) and fixed by commit 6aacd1484468 (virtio-net: fix overflow inside virtnet_rq_alloc).

Red Hat rates this vulnerability as Moderate, and Ubuntu rates it as Medium.

Symptoms

An affected ECS instance may show the following symptoms:

  • Unexpected instance crash — The instance crashes without warning (kernel panic), and the dmesg log contains entries related to general protection fault or pagealloc: memory corruption.

  • Large file transfer failure — A transfer of a file of about 100 MB or larger over scp is interrupted.

  • Silent corruption of kernel data structures — Page table pages, slab objects, buffer_head structures, and similar data are unexpectedly overwritten, which leads to unpredictable system behavior.

Affected scope

The following table lists the ECS official Linux images evaluated for CVE-2024-57843, why each distribution is affected, and the fix status of the corresponding ECS images.

DistributionAffected versionCauseFix status of ECS images
Ubuntu24.04 LTSAffected from the first release, because the 6.8 kernel baseline includes the defect-introducing patch that was backported to 6.6. Fixed in 6.8.0-58.60.Images released in May 2025 are fixed (6.8.0-60-generic).
CentOS Stream 99Follows RHEL upstream. Fixed in 5.14.0-570.12.1.el9_6.The patched images released in March 2025 are fixed.
Fedora40 (EOL)Introduced in kernel-6.6.2-201.fc40. Fixed in 6.12.5-200.Reached EOL. No update is planned.

Check whether your instance is affected

The running kernel version determines whether an ECS instance contains the defect. Run the following command on the instance to get the running kernel version:

uname -r

Compare the output with the fix version listed for your distribution in the affected scope table:

  • Earlier than the fix version — The instance is affected. Upgrade the kernel and restart the instance.

  • The fix version or later — The running kernel contains the fix, and no further action is required.

The trigger conditions described in the root cause section determine whether the defect is triggered at runtime. They do not determine whether the running kernel contains the defect, so use the kernel version as the decision criterion.

Fix an affected instance

For all distributions, the fix requires you to upgrade the kernel packages and restart the instance before the fix takes effect.

Important

Restarting the instance interrupts every service running on it. Plan the restart before you upgrade the kernel.

Ubuntu 24.04 LTS

Upgrade the kernel to 6.8.0-58-generic (package version 6.8.0-58.60) or later.

  1. Confirm that a qualifying kernel version is available. The following commands refresh the package index and list the linux-image-generic versions offered by your configured repositories.

    sudo apt update
    apt-cache madison linux-image-generic
  2. Upgrade the kernel packages.

    sudo apt install -y --only-upgrade linux-image-generic
  3. Restart the instance.

    sudo reboot
  4. After the restart, confirm the running kernel version.

    uname -r

    Verify that the output is 6.8.0-58-generic or later.

Note

Ubuntu reports the same kernel as 6.8.0-58-generic in uname -r output and as 6.8.0-58.60 in package metadata. The 6.8.0-60-generic kernel shipped in ECS images released in May 2025 is later than 6.8.0-58-generic and therefore contains the fix.

CentOS Stream 9

Upgrade the kernel to kernel-5.14.0-570.12.1.el9_6 or later.

  1. Upgrade the kernel packages.

    sudo dnf clean all && sudo dnf makecache
    sudo dnf -y update kernel
  2. Restart the instance.

    sudo reboot
  3. After the restart, confirm the running kernel version.

    uname -r

    Verify that the output is 5.14.0-570.12.1.el9_6 or later.

Fedora 40 (EOL)

Fedora 40 has reached EOL and is no longer maintained, and no update is planned for the ECS official Fedora 40 images. Upgrade to Fedora 41 or later.

If you continue to run Fedora 40, upgrade the kernel to 6.12.5-200 or later.

  1. Upgrade the kernel packages.

    sudo dnf clean all && sudo dnf makecache
    sudo dnf -y update kernel
  2. Restart the instance.

    sudo reboot
  3. After the restart, confirm the running kernel version.

    uname -r

    Verify that the output is 6.12.5-200 or later.

Temporary mitigation

No temporary mitigation is available for CVE-2024-57843. Upgrade to a kernel version that contains the fix. Changing any of the trigger conditions described in the root cause section is not a substitute for the kernel upgrade.

Warning

Do not set net.core.high_order_alloc_disable=1 in production environments. On kernel versions that contain the vulnerability, this parameter significantly increases the probability that the vulnerability is triggered. Kernel versions without the vulnerability are not affected.

Root cause

CVE-2024-57843 is a 16-byte cross-page overflow that occurs when the virtio-net driver fills mergeable RX buffers with data.

In premapped DMA mode (do_dma=true), each frag page must reserve 16 bytes at the start of the page to store mapping information. When all of the conditions in the following table are met, the driver allocates a 4096-byte (order-0) page but must write 16 + 4096 = 4112 bytes. The last 16 bytes are written to the physically adjacent next page, which silently corrupts memory.

No.Trigger conditionDescription
1premapped DMA is active16 bytes must be reserved at the start of the page.
2mergeable RX buffers are used and XDP is disabledDetermines the code path that calculates the buffer length.
3MTU >= 4084 and the EWMA of the traffic packet length > 4020Saturates len to 4096.
4The frag page falls back from order-3 to order-0 (transient memory pressure)An order-3 page (32 KB) has enough space, but an order-0 page (4 KB) does not.

Prevent new instances from being affected

When you create an ECS instance, use an official image that already contains the fix.

If crashes persist after the upgrade

If similar crashes still occur after you upgrade the kernel, collect the vmcore file and submit a ticket for troubleshooting assistance.

References