目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-26620— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于 s390/vfio-ap 中存在安全问题。

CVSS 8.2 · High EPSS 0.63% · P49

可能的 ATT&CK 技术 1 AI

T1059.004 · Unix Shell

影响版本矩阵 10

厂商产品 版本范围状态
Linux Linux 48cae940c31d2407d860d87c41d5f9871c0521db< d6b8d034b576f406af920a7bee81606c027b24c6 affected
48cae940c31d2407d860d87c41d5f9871c0521db< c69d821197611678533fb3eb784fc823b921349a affected
48cae940c31d2407d860d87c41d5f9871c0521db< cdd134d56138302976685e6c7bc4755450b3880e affected
48cae940c31d2407d860d87c41d5f9871c0521db< 850fb7fa8c684a4c6bf0e4b6978f4ddcc5d43d11 affected
6.0 affected
< 6.0 unaffected
6.1.76≤ 6.1.* unaffected
6.6.15≤ 6.6.* unaffected
… +2 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-26620 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
s390/vfio-ap: always filter entire AP matrix
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: always filter entire AP matrix The vfio_ap_mdev_filter_matrix function is called whenever a new adapter or domain is assigned to the mdev. The purpose of the function is to update the guest's AP configuration by filtering the matrix of adapters and domains assigned to the mdev. When an adapter or domain is assigned, only the APQNs associated with the APID of the new adapter or APQI of the new domain are inspected. If an APQN does not reference a queue device bound to the vfio_ap device driver, then it's APID will be filtered from the mdev's matrix when updating the guest's AP configuration. Inspecting only the APID of the new adapter or APQI of the new domain will result in passing AP queues through to a guest that are not bound to the vfio_ap device driver under certain circumstances. Consider the following: guest's AP configuration (all also assigned to the mdev's matrix): 14.0004 14.0005 14.0006 16.0004 16.0005 16.0006 unassign domain 4 unbind queue 16.0005 assign domain 4 When domain 4 is re-assigned, since only domain 4 will be inspected, the APQNs that will be examined will be: 14.0004 16.0004 Since both of those APQNs reference queue devices that are bound to the vfio_ap device driver, nothing will get filtered from the mdev's matrix when updating the guest's AP configuration. Consequently, queue 16.0005 will get passed through despite not being bound to the driver. This violates the linux device model requirement that a guest shall only be given access to devices bound to the device driver facilitating their pass-through. To resolve this problem, every adapter and domain assigned to the mdev will be inspected when filtering the mdev's matrix.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于 s390/vfio-ap 中存在安全问题。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 48cae940c31d2407d860d87c41d5f9871c0521db ~ d6b8d034b576f406af920a7bee81606c027b24c6 -
Linux Linux 6.0 -

二、漏洞 CVE-2024-26620 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-26620 的情报信息

请登录查看更多情报信息。

CVE-2024-26620 其他参考 (3)

同批安全公告 · Linux · 2024-02-29 · 共 53 条

CVE-2023-52480 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2023-52478 8.8 HIGH Linux kernel 安全漏洞
CVE-2023-52479 8.8 HIGH Linux kernel 安全漏洞
CVE-2021-47068 7.8 HIGH Linux kernel 安全漏洞
CVE-2023-52491 7.8 HIGH Linux kernel 安全漏洞
CVE-2023-52486 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26608 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26610 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26614 7.8 HIGH Linux kernel安全漏洞
CVE-2023-52483 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26617 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47060 7.8 HIGH Linux kernel 安全漏洞
CVE-2021-47061 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26611 7.5 HIGH Linux kernel 安全漏洞
CVE-2021-47066 7.1 HIGH Linux kernel 安全漏洞
CVE-2021-47055 7.1 HIGH Linux kernel 安全漏洞
CVE-2023-52497 7.1 HIGH Linux kernel 安全漏洞
CVE-2021-47056 Linux kernel 安全漏洞
CVE-2021-47058 Linux kernel 安全漏洞
CVE-2021-47054 Linux kernel 安全漏洞

显示前 20 条,共 53 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26620

暂无评论


发表评论