目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-35969— Linux kernel 安全漏洞

CVSS 8.8 · High EPSS 0.37% · P30

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinux5c578aedcb21d79eeb4e9cf04ca5b276ac82614c< b4b3b69a19016d4e7fbdbd1dbcc184915eb862e1affected
5c578aedcb21d79eeb4e9cf04ca5b276ac82614c< cca606e14264098cba65efa82790825dbf69e903affected
5c578aedcb21d79eeb4e9cf04ca5b276ac82614c< 3fb02ec57ead2891a2306af8c51a306bc5945e70affected
5c578aedcb21d79eeb4e9cf04ca5b276ac82614c< 4b19e9507c275de0cfe61c24db69179dc52cf9fbaffected
5c578aedcb21d79eeb4e9cf04ca5b276ac82614c< de76ae9ea1a6cf9e77fcec4f2df2904e26c23cebaffected
5c578aedcb21d79eeb4e9cf04ca5b276ac82614c< 01b11a0566670612bd464a932e5ac2eae53d8652affected
5c578aedcb21d79eeb4e9cf04ca5b276ac82614c< 6cdb20c342cd0193d3e956e3d83981d0f438bb83affected
5c578aedcb21d79eeb4e9cf04ca5b276ac82614c< 7633c4da919ad51164acbf1aa322cc1a3ead6129affected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-35969 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ipv6: fix race condition between ipv6_get_ifaddr and ipv6_del_addr Although ipv6_get_ifaddr walks inet6_addr_lst under the RCU lock, it still means hlist_for_each_entry_rcu can return an item that got removed from the list. The memory itself of such item is not freed thanks to RCU but nothing guarantees the actual content of the memory is sane. In particular, the reference count can be zero. This can happen if ipv6_del_addr is called in parallel. ipv6_del_addr removes the entry from inet6_addr_lst (hlist_del_init_rcu(&ifp->addr_lst)) and drops all references (__in6_ifa_put(ifp) + in6_ifa_put(ifp)). With bad enough timing, this can happen: 1. In ipv6_get_ifaddr, hlist_for_each_entry_rcu returns an entry. 2. Then, the whole ipv6_del_addr is executed for the given entry. The reference count drops to zero and kfree_rcu is scheduled. 3. ipv6_get_ifaddr continues and tries to increments the reference count (in6_ifa_hold). 4. The rcu is unlocked and the entry is freed. 5. The freed entry is returned. Prevent increasing of the reference count in such case. The name in6_ifa_hold_safe is chosen to mimic the existing fib6_info_hold_safe. [ 41.506330] refcount_t: addition on 0; use-after-free. [ 41.506760] WARNING: CPU: 0 PID: 595 at lib/refcount.c:25 refcount_warn_saturate+0xa5/0x130 [ 41.507413] Modules linked in: veth bridge stp llc [ 41.507821] CPU: 0 PID: 595 Comm: python3 Not tainted 6.9.0-rc2.main-00208-g49563be82afa #14 [ 41.508479] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) [ 41.509163] RIP: 0010:refcount_warn_saturate+0xa5/0x130 [ 41.509586] Code: ad ff 90 0f 0b 90 90 c3 cc cc cc cc 80 3d c0 30 ad 01 00 75 a0 c6 05 b7 30 ad 01 01 90 48 c7 c7 38 cc 7a 8c e8 cc 18 ad ff 90 <0f> 0b 90 90 c3 cc cc cc cc 80 3d 98 30 ad 01 00 0f 85 75 ff ff ff [ 41.510956] RSP: 0018:ffffbda3c026baf0 EFLAGS: 00010282 [ 41.511368] RAX: 0000000000000000 RBX: ffff9e9c46914800 RCX: 0000000000000000 [ 41.511910] RDX: ffff9e9c7ec29c00 RSI: ffff9e9c7ec1c900 RDI: ffff9e9c7ec1c900 [ 41.512445] RBP: ffff9e9c43660c9c R08: 0000000000009ffb R09: 00000000ffffdfff [ 41.512998] R10: 00000000ffffdfff R11: ffffffff8ca58a40 R12: ffff9e9c4339a000 [ 41.513534] R13: 0000000000000001 R14: ffff9e9c438a0000 R15: ffffbda3c026bb48 [ 41.514086] FS: 00007fbc4cda1740(0000) GS:ffff9e9c7ec00000(0000) knlGS:0000000000000000 [ 41.514726] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 41.515176] CR2: 000056233b337d88 CR3: 000000000376e006 CR4: 0000000000370ef0 [ 41.515713] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 41.516252] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 41.516799] Call Trace: [ 41.517037] <TASK> [ 41.517249] ? __warn+0x7b/0x120 [ 41.517535] ? refcount_warn_saturate+0xa5/0x130 [ 41.517923] ? report_bug+0x164/0x190 [ 41.518240] ? handle_bug+0x3d/0x70 [ 41.518541] ? exc_invalid_op+0x17/0x70 [ 41.520972] ? asm_exc_invalid_op+0x1a/0x20 [ 41.521325] ? refcount_warn_saturate+0xa5/0x130 [ 41.521708] ipv6_get_ifaddr+0xda/0xe0 [ 41.522035] inet6_rtm_getaddr+0x342/0x3f0 [ 41.522376] ? __pfx_inet6_rtm_getaddr+0x10/0x10 [ 41.522758] rtnetlink_rcv_msg+0x334/0x3d0 [ 41.523102] ? netlink_unicast+0x30f/0x390 [ 41.523445] ? __pfx_rtnetlink_rcv_msg+0x10/0x10 [ 41.523832] netlink_rcv_skb+0x53/0x100 [ 41.524157] netlink_unicast+0x23b/0x390 [ 41.524484] netlink_sendmsg+0x1f2/0x440 [ 41.524826] __sys_sendto+0x1d8/0x1f0 [ 41.525145] __x64_sys_sendto+0x1f/0x30 [ 41.525467] do_syscall_64+0xa5/0x1b0 [ 41.525794] entry_SYSCALL_64_after_hwframe+0x72/0x7a [ 41.526213] RIP: 0033:0x7fbc4cfcea9a [ 41.526528] Code: d8 64 89 02 48 c7 c0 ff ff ff ff eb b8 0f 1f 00 f3 0f 1e fa 41 89 ca 64 8b 04 25 18 00 00 00 85 c0 75 15 b8 2c 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 7e c3 0f 1f 44 00 00 41 54 48 83 ec 30 44 89 [ 41.527942] RSP: 002b:00007f ---truncated---
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在竞争条件。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 5c578aedcb21d79eeb4e9cf04ca5b276ac82614c ~ b4b3b69a19016d4e7fbdbd1dbcc184915eb862e1 -
LinuxLinux 2.6.35 -

二、漏洞 CVE-2024-35969 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-35969 的情报信息

登录查看更多情报信息。

CVE-2024-35969 邮件列表归档 (2)

CVE-2024-35969 其他参考 (8)

同批安全公告 · Linux · 2024-05-20 · 共 62 条

CVE-2024-359808.4 HIGHLinux kernel 安全漏洞
CVE-2024-359878.4 HIGHLinux kernel 安全漏洞
CVE-2024-359687.8 HIGHLinux kernel 安全漏洞
CVE-2024-360017.8 HIGHLinux kernel 安全漏洞
CVE-2024-359497.8 HIGHLinux kernel 安全漏洞
CVE-2024-359507.8 HIGHLinux kernel 安全漏洞
CVE-2024-359517.8 HIGHLinux kernel 安全漏洞
CVE-2024-359547.8 HIGHLinux kernel 安全漏洞
CVE-2024-360077.8 HIGHLinux kernel 安全漏洞
CVE-2024-359937.8 HIGHLinux kernel 安全漏洞
CVE-2024-359947.8 HIGHLinux kernel 安全漏洞
CVE-2024-359907.8 HIGHLinux kernel 安全漏洞
CVE-2024-359587.8 HIGHLinux kernel 安全漏洞
CVE-2024-360097.8 HIGHLinux kernel 安全漏洞
CVE-2024-359797.8 HIGHLinux kernel 安全漏洞
CVE-2024-359487.8 HIGHLinux kernel 安全漏洞
CVE-2024-359987.5 HIGHLinux kernel 安全漏洞
CVE-2024-359997.5 HIGHLinux kernel 安全漏洞
CVE-2024-359717.5 HIGHLinux kernel 安全漏洞
CVE-2024-359627.1 HIGHLinux kernel 安全漏洞

显示前 20 条,共 62 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-35969

暂无评论


发表评论