目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-36020— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.26% · P17

影响版本矩阵 24

厂商产品版本范围状态
LinuxLinux76ed715836c6994bac29d9638e9314e6e3b08651< cc9cd02dd9e8b7764ea9effb24f4f1dd73d1b23daffected
e88c2a1e28c5475065563d66c07ca879a9afbd07< 9dcf0fcb80f6aeb01469e3c957f8d4c97365450aaffected
9abae363af5ced6adbf04c14366289540281fb26< b8e82128b44fa40bf99a50b919488ef361e1683caffected
c39de3ae5075ea5f78e097cb5720d4e52d5caed9< 951d2748a2a8242853abc3d0c153ce4bf8faad31affected
52424f974bc53c26ba3f00300a00e9de9afcd972< 3e89846283f3cf7c7a8e28b342576fd7c561d2baaffected
52424f974bc53c26ba3f00300a00e9de9afcd972< 0dcf573f997732702917af1563aa2493dc772fc0affected
52424f974bc53c26ba3f00300a00e9de9afcd972< 06df7618f591b2dc43c59967e294d7b9fc8675b6affected
52424f974bc53c26ba3f00300a00e9de9afcd972< f37c4eac99c258111d414d31b740437e1925b8e8affected
… +16 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-36020 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
i40e: fix vf may be used uninitialized in this function warning
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: i40e: fix vf may be used uninitialized in this function warning To fix the regression introduced by commit 52424f974bc5, which causes servers hang in very hard to reproduce conditions with resets races. Using two sources for the information is the root cause. In this function before the fix bumping v didn't mean bumping vf pointer. But the code used this variables interchangeably, so stale vf could point to different/not intended vf. Remove redundant "v" variable and iterate via single VF pointer across whole function instead to guarantee VF pointer validity.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于 i40e 模块存在漏洞。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 76ed715836c6994bac29d9638e9314e6e3b08651 ~ cc9cd02dd9e8b7764ea9effb24f4f1dd73d1b23d -
LinuxLinux 6.1 -

二、漏洞 CVE-2024-36020 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-36020 的情报信息

登录查看更多情报信息。

CVE-2024-36020 邮件列表归档 (2)

CVE-2024-36020 其他参考 (7)

同批安全公告 · Linux · 2024-05-30 · 共 93 条

CVE-2024-369589.8 CRITICALLinux kernel 安全漏洞
CVE-2024-368869.8 CRITICALLinux kernel 安全漏洞
CVE-2024-369119.8 CRITICALLinux kernel 安全漏洞
CVE-2024-369129.6 CRITICALLinux kernel 安全漏洞
CVE-2024-369139.3 CRITICALLinux kernel 安全漏洞
CVE-2024-369099.3 CRITICALLinux kernel 安全漏洞
CVE-2024-369228.8 HIGHLinux kernel 安全漏洞
CVE-2024-369218.8 HIGHLinux kernel 安全漏洞
CVE-2024-369108.4 HIGHLinux kernel 安全漏洞
CVE-2024-360328.1 HIGHLinux kernel安全漏洞
CVE-2024-369337.8 HIGHLinux kernel 安全漏洞
CVE-2024-369047.8 HIGHLinux kernel 安全漏洞
CVE-2024-369147.8 HIGHLinux kernel 安全漏洞
CVE-2024-369187.8 HIGHLinux kernel 安全漏洞
CVE-2024-360187.8 HIGHLinux kernel 安全漏洞
CVE-2024-368947.8 HIGHLinux kernel 安全漏洞
CVE-2024-368907.8 HIGHLinux kernel 安全漏洞
CVE-2024-369407.8 HIGHLinux kernel 安全漏洞
CVE-2024-369287.8 HIGHLinux kernel 安全漏洞
CVE-2024-368847.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 93 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-36020

暂无评论


发表评论