目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-36016— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.27% · P18

影响版本矩阵 20

厂商产品版本范围状态
LinuxLinuxe1eaea46bb4020b38a141b84f88565d4603f8dd0< 9513d4148950b05bc99fa7314dc883cc0e1605e5affected
e1eaea46bb4020b38a141b84f88565d4603f8dd0< b229bc6c6ea9fe459fc3fa94fd0a27a2f32aca56affected
e1eaea46bb4020b38a141b84f88565d4603f8dd0< 0fb736c9931e02dbc7d9a75044c8e1c039e50f04affected
e1eaea46bb4020b38a141b84f88565d4603f8dd0< 4c267110fc110390704cc065edb9817fdd10ff54affected
e1eaea46bb4020b38a141b84f88565d4603f8dd0< 46f52c89a7e7d2691b97a9728e4591d071ca8abcaffected
e1eaea46bb4020b38a141b84f88565d4603f8dd0< 774d83b008eccb1c48c14dc5486e7aa255731350affected
e1eaea46bb4020b38a141b84f88565d4603f8dd0< f126ce7305fe88f49cdabc6db4168b9318898ea3affected
e1eaea46bb4020b38a141b84f88565d4603f8dd0< b890d45aaf02b564e6cae2d2a590f9649330857daffected
… +12 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-36016 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
tty: n_gsm: fix possible out-of-bounds in gsm0_receive()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() Assuming the following: - side A configures the n_gsm in basic option mode - side B sends the header of a basic option mode frame with data length 1 - side A switches to advanced option mode - side B sends 2 data bytes which exceeds gsm->len Reason: gsm->len is not used in advanced option mode. - side A switches to basic option mode - side B keeps sending until gsm0_receive() writes past gsm->buf Reason: Neither gsm->state nor gsm->len have been reset after reconfiguration. Fix this by changing gsm->count to gsm->len comparison from equal to less than. Also add upper limit checks against the constant MAX_MRU in gsm0_receive() and gsm1_receive() to harden against memory corruption of gsm->len and gsm->mru. All other checks remain as we still need to limit the data according to the user configuration and actual payload size.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于存在越界写入,会导致内存损坏。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux e1eaea46bb4020b38a141b84f88565d4603f8dd0 ~ 9513d4148950b05bc99fa7314dc883cc0e1605e5 -
LinuxLinux 2.6.35 -

二、漏洞 CVE-2024-36016 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-36016 的情报信息

登录查看更多情报信息。

CVE-2024-36016 邮件列表归档 (1)

CVE-2024-36016 其他参考 (9)

同批安全公告 · Linux · 2024-05-29 · 共 4 条

CVE-2023-528819.8 CRITICALLinux kernel 安全漏洞
CVE-2024-36015Linux kernel 安全漏洞
CVE-2024-36014Linux kernel 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2024-36016

暂无评论


发表评论