CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's sch_cake ACK filter, which improperly handles malformed IP headers, potentially leading to excessive warning messages in the system log or a system panic if configured to do so. While the existing code skips the problematic packets, the unnecessary WARN_ON(1) could disrupt system stability. Linux system administrators and developers utilizing the sch_cake queueing discipline should prioritize addressing this issue to enhance system reliability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set. The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.