目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-26687— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于shutdown_pirq 和startup_pirq两者都是在 irq_desc->lock 被占用的情况下调用的。

AI 预测 5.5 利用难度: 中等 EPSS 0.23% · P13

可能的 ATT&CK 技术 1 AI

T1499 · Endpoint Denial of Service

影响版本矩阵 16

厂商产品 版本范围状态
Linux Linux d46a78b05c0e37f76ddf4a7a67bf0b6c68bada55< 9470f5b2503cae994098dea9682aee15b313fa44 affected
d46a78b05c0e37f76ddf4a7a67bf0b6c68bada55< 0fc88aeb2e32b76db3fe6a624b8333dbe621b8fd affected
d46a78b05c0e37f76ddf4a7a67bf0b6c68bada55< ea592baf9e41779fe9a0424c03dd2f324feca3b3 affected
d46a78b05c0e37f76ddf4a7a67bf0b6c68bada55< 585a344af6bcac222608a158fc2830ff02712af5 affected
d46a78b05c0e37f76ddf4a7a67bf0b6c68bada55< 20980195ec8d2e41653800c45c8c367fa1b1f2b4 affected
d46a78b05c0e37f76ddf4a7a67bf0b6c68bada55< 9be71aa12afa91dfe457b3fb4a444c42b1ee036b affected
d46a78b05c0e37f76ddf4a7a67bf0b6c68bada55< fa765c4b4aed2d64266b694520ecb025c862c5a9 affected
2.6.37 affected
… +8 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-26687 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
xen/events: close evtchn after mapping cleanup
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: xen/events: close evtchn after mapping cleanup shutdown_pirq and startup_pirq are not taking the irq_mapping_update_lock because they can't due to lock inversion. Both are called with the irq_desc->lock being taking. The lock order, however, is first irq_mapping_update_lock and then irq_desc->lock. This opens multiple races: - shutdown_pirq can be interrupted by a function that allocates an event channel: CPU0 CPU1 shutdown_pirq { xen_evtchn_close(e) __startup_pirq { EVTCHNOP_bind_pirq -> returns just freed evtchn e set_evtchn_to_irq(e, irq) } xen_irq_info_cleanup() { set_evtchn_to_irq(e, -1) } } Assume here event channel e refers here to the same event channel number. After this race the evtchn_to_irq mapping for e is invalid (-1). - __startup_pirq races with __unbind_from_irq in a similar way. Because __startup_pirq doesn't take irq_mapping_update_lock it can grab the evtchn that __unbind_from_irq is currently freeing and cleaning up. In this case even though the event channel is allocated, its mapping can be unset in evtchn_to_irq. The fix is to first cleanup the mappings and then close the event channel. In this way, when an event channel gets allocated it's potential previous evtchn_to_irq mappings are guaranteed to be unset already. This is also the reverse order of the allocation where first the event channel is allocated and then the mappings are setup. On a 5.10 kernel prior to commit 3fcdaf3d7634 ("xen/events: modify internal [un]bind interfaces"), we hit a BUG like the following during probing of NVMe devices. The issue is that during nvme_setup_io_queues, pci_free_irq is called for every device which results in a call to shutdown_pirq. With many nvme devices it's therefore likely to hit this race during boot because there will be multiple calls to shutdown_pirq and startup_pirq are running potentially in parallel. ------------[ cut here ]------------ blkfront: xvda: barrier or flush: disabled; persistent grants: enabled; indirect descriptors: enabled; bounce buffer: enabled kernel BUG at drivers/xen/events/events_base.c:499! invalid opcode: 0000 [#1] SMP PTI CPU: 44 PID: 375 Comm: kworker/u257:23 Not tainted 5.10.201-191.748.amzn2.x86_64 #1 Hardware name: Xen HVM domU, BIOS 4.11.amazon 08/24/2006 Workqueue: nvme-reset-wq nvme_reset_work RIP: 0010:bind_evtchn_to_cpu+0xdf/0xf0 Code: 5d 41 5e c3 cc cc cc cc 44 89 f7 e8 2b 55 ad ff 49 89 c5 48 85 c0 0f 84 64 ff ff ff 4c 8b 68 30 41 83 fe ff 0f 85 60 ff ff ff <0f> 0b 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00 RSP: 0000:ffffc9000d533b08 EFLAGS: 00010046 RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000006 RDX: 0000000000000028 RSI: 00000000ffffffff RDI: 00000000ffffffff RBP: ffff888107419680 R08: 0000000000000000 R09: ffffffff82d72b00 R10: 0000000000000000 R11: 0000000000000000 R12: 00000000000001ed R13: 0000000000000000 R14: 00000000ffffffff R15: 0000000000000002 FS: 0000000000000000(0000) GS:ffff88bc8b500000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 0000000002610001 CR4: 00000000001706e0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: ? show_trace_log_lvl+0x1c1/0x2d9 ? show_trace_log_lvl+0x1c1/0x2d9 ? set_affinity_irq+0xdc/0x1c0 ? __die_body.cold+0x8/0xd ? die+0x2b/0x50 ? do_trap+0x90/0x110 ? bind_evtchn_to_cpu+0xdf/0xf0 ? do_error_trap+0x65/0x80 ? bind_evtchn_to_cpu+0xdf/0xf0 ? exc_invalid_op+0x4e/0x70 ? bind_evtchn_to_cpu+0xdf/0xf0 ? asm_exc_invalid_op+0x12/0x20 ? bind_evtchn_to_cpu+0xdf/0x ---truncated---
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于shutdown_pirq 和startup_pirq两者都是在 irq_desc->lock 被占用的情况下调用的。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux d46a78b05c0e37f76ddf4a7a67bf0b6c68bada55 ~ 9470f5b2503cae994098dea9682aee15b313fa44 -
Linux Linux 2.6.37 -

二、漏洞 CVE-2024-26687 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-26687 的情报信息

请登录查看更多情报信息。

CVE-2024-26687 邮件列表归档 (1)

CVE-2024-26687 其他参考 (4)

同批安全公告 · Linux · 2024-04-03 · 共 94 条

CVE-2024-26760 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2024-26779 8.8 HIGH Linux kernel 安全漏洞
CVE-2024-26689 8.8 HIGH Linux kernel 安全漏洞
CVE-2024-26692 8.3 HIGH Linux kernel 安全漏洞
CVE-2024-26736 8.1 HIGH Linux kernel 安全漏洞
CVE-2024-26699 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26739 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26762 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26766 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26772 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26773 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26748 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26697 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26737 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26718 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26712 7.8 HIGH Linux kernel 安全漏洞
CVE-2023-52637 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26706 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26728 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-26704 7.8 HIGH Linux kernel 安全漏洞

显示前 20 条,共 94 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26687

暂无评论


发表评论