Vulnary
← back to the feed
Critical· 9.8official fix available

CVE-2024-45030

A critical vulnerability in the Linux kernel's igb driver causes payload corruption during network transmission when MAX_SKB_FRAGS is set too high. The issue arises from improper handling of buffer sizes, leading to data corruption. A fix exists in updated kernel versions that address this buffer size calculation.

publishedSep 11, 2024
last modifiedAug 4, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
11th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Systems using the igb network driver in Linux kernels, particularly versions 6.11 and earlier.

02

Real-world impact

Could allow attackers to corrupt transmitted data, potentially leading to service disruption or data integrity issues.

03

Why this severity

CVSS 9.8 (critical): High confidence in exploitation, high impact on confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade the Linux kernel to version 6.11 or later, which includes the fix for MAX_SKB_FRAGS handling.
  2. 02Apply the kernel update through standard package management tools (e.g., apt, yum) or vendor-provided tools.

NVD description stating the vulnerability has been resolved in updated kernel versions.

05

Timeline

  1. Sep 11, 2024 · Sep 11, 2024
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
  3. Aug 5, 2026 · 1d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →