{"id":82557,"date":"2026-07-26T10:46:39","date_gmt":"2026-07-26T07:16:39","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2024-14040-net-nexthop-increase-weight-to-u16\/"},"modified":"2026-07-26T10:46:39","modified_gmt":"2026-07-26T07:16:39","slug":"cve-2024-14040-net-nexthop-increase-weight-to-u16","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2024-14040-net-nexthop-increase-weight-to-u16\/","title":{"rendered":"CVE-2024-14040 &#8211; net: nexthop: Increase weight to u16"},"content":{"rendered":"<p>CVE ID :CVE-2024-14040<\/p>\n<p>  Published : July 26, 2026, 7:16 a.m. | 37\u00a0minutes ago<\/p>\n<p>  Description :In the Linux kernel, the following vulnerability has been resolved:<\/p>\n<p>net: nexthop: Increase weight to u16<\/p>\n<p>In CLOS networks, as link failures occur at various points in the network,<br \/>\nECMP weights of the involved nodes are adjusted to compensate. With high<br \/>\nfan-out of the involved nodes, and overall high number of nodes,<br \/>\na (non-)ECMP weight ratio that we would like to configure does not fit into<br \/>\n8 bits. Instead of, say, 255:254, we might like to configure something like<br \/>\n1000:999. For these deployments, the 8-bit weight may not be enough.<\/p>\n<p>To that end, in this patch increase the next hop weight from u8 to u16.<\/p>\n<p>Increasing the width of an integral type can be tricky, because while the<br \/>\ncode still compiles, the types may not check out anymore, and numerical<br \/>\nerrors come up. To prevent this, the conversion was done in two steps.<br \/>\nFirst the type was changed from u8 to a single-member structure, which<br \/>\ninvalidated all uses of the field. This allowed going through them one by<br \/>\none and audit for type correctness. Then the structure was replaced with a<br \/>\nvanilla u16 again. This should ensure that no place was missed.<\/p>\n<p>The UAPI for configuring nexthop group members is that an attribute<br \/>\nNHA_GROUP carries an array of struct nexthop_grp entries:<\/p>\n<p>\tstruct nexthop_grp {<br \/>\n\t\t__u32\tid;\t  \/* nexthop id &#8211; must exist *\/<br \/>\n\t\t__u8\tweight;   \/* weight of this nexthop *\/<br \/>\n\t\t__u8\tresvd1;<br \/>\n\t\t__u16\tresvd2;<br \/>\n\t};<\/p>\n<p>The field resvd1 is currently validated and required to be zero. We can<br \/>\nlift this requirement and carry high-order bits of the weight in the<br \/>\nreserved field:<\/p>\n<p>\tstruct nexthop_grp {<br \/>\n\t\t__u32\tid;\t  \/* nexthop id &#8211; must exist *\/<br \/>\n\t\t__u8\tweight;   \/* weight of this nexthop *\/<br \/>\n\t\t__u8\tweight_high;<br \/>\n\t\t__u16\tresvd2;<br \/>\n\t};<\/p>\n<p>Keeping the fields split this way was chosen in case an existing userspace<br \/>\nmakes assumptions about the width of the weight field, and to sidestep any<br \/>\nendianness issues.<\/p>\n<p>The weight field is currently encoded as the weight value minus one,<br \/>\nbecause weight of 0 is invalid. This same trick is impossible for the new<br \/>\nweight_high field, because zero must mean actual zero. With this in place:<\/p>\n<p>&#8211; Old userspace is guaranteed to carry weight_high of 0, therefore<br \/>\n  configuring 8-bit weights as appropriate. When dumping nexthops with<br \/>\n  16-bit weight, it would only show the lower 8 bits. But configuring such<br \/>\n  nexthops implies existence of userspace aware of the extension in the<br \/>\n  first place.<\/p>\n<p>&#8211; New userspace talking to an old kernel will work as long as it only<br \/>\n  attempts to configure 8-bit weights, where the high-order bits are zero.<br \/>\n  Old kernel will bounce attempts at configuring &gt;8-bit weights.<\/p>\n<p>Renaming reserved fields as they are allocated for some purpose is commonly<br \/>\ndone in Linux. Whoever touches a reserved field is doing so at their own<br \/>\nrisk. nexthop_grp::resvd1 in particular is currently used by at least<br \/>\nstrace, however they carry an own copy of UAPI headers, and the conversion<br \/>\nshould be trivial. A helper is provided for decoding the weight out of the<br \/>\ntwo fields. Forcing a conversion seems preferable to bending backwards and<br \/>\nintroducing anonymous unions or whatever.<\/p>\n<p>  Severity: 0.0 | NA<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2024-14040 Published : July 26, 2026, 7:16 a.m. | 37\u00a0minutes ago Description :In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various points in the network, ECMP weights of the involved nodes are adjusted to compensate. With high &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-82557","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/82557","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=82557"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/82557\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=82557"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=82557"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=82557"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}