目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-36244— Linux kernel 安全漏洞

AI 预测 4.3 利用难度: 中等 EPSS 0.25% · P16

可能的 ATT&CK 技术 1AI

T1134 · Access Token Manipulation

影响版本矩阵 14

厂商产品版本范围状态
LinuxLinuxb5b73b26b3ca34574124ed7ae9c5ba8391a7f176< 34d83c3e6e97867ae061d14eb52123404aab1cbcaffected
b5b73b26b3ca34574124ed7ae9c5ba8391a7f176< b939d1e04a90248b4cdf417b0969c270ceb992b2affected
b5b73b26b3ca34574124ed7ae9c5ba8391a7f176< 91f249b01fe490fce11fbb4307952ca8cce78724affected
b5b73b26b3ca34574124ed7ae9c5ba8391a7f176< fb66df20a7201e60f2b13d7f95d031b31a8831d3affected
83bd58952b2b8543d8c48d1453975ab47a0a7504affected
817ff50796c5e364c879596509f83fcba194bb6faffected
5.4.68< 5.5affected
5.8.12< 5.9affected
… +6 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-36244 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
net/sched: taprio: extend minimum interval restriction to entire cycle too
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: extend minimum interval restriction to entire cycle too It is possible for syzbot to side-step the restriction imposed by the blamed commit in the Fixes: tag, because the taprio UAPI permits a cycle-time different from (and potentially shorter than) the sum of entry intervals. We need one more restriction, which is that the cycle time itself must be larger than N * ETH_ZLEN bit times, where N is the number of schedule entries. This restriction needs to apply regardless of whether the cycle time came from the user or was the implicit, auto-calculated value, so we move the existing "cycle == 0" check outside the "if "(!new->cycle_time)" branch. This way covers both conditions and scenarios. Add a selftest which illustrates the issue triggered by syzbot.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于net/sched:taprio模块将最小间隔限制扩展到整个周期。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux b5b73b26b3ca34574124ed7ae9c5ba8391a7f176 ~ 34d83c3e6e97867ae061d14eb52123404aab1cbc -
LinuxLinux 5.9 -

二、漏洞 CVE-2024-36244 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-36244 的情报信息

登录查看更多情报信息。

CVE-2024-36244 补丁与修复 (1)

CVE-2024-36244 其他参考 (3)

同批安全公告 · Linux · 2024-06-21 · 共 40 条

CVE-2024-38636Linux kernel 安全漏洞
CVE-2024-38627Linux kernel 安全漏洞
CVE-2024-38628Linux kernel 安全漏洞
CVE-2024-38629Linux kernel 安全漏洞
CVE-2024-38630Linux kernel 安全漏洞
CVE-2024-38631Linux kernel 安全漏洞
CVE-2024-38632Linux kernel 安全漏洞
CVE-2024-38633Linux kernel 安全漏洞
CVE-2024-38634Linux kernel 安全漏洞
CVE-2024-38635Linux kernel 安全漏洞
CVE-2024-38625Linux kernel 安全漏洞
CVE-2024-38637Linux kernel 安全漏洞
CVE-2024-38659Linux kernel 安全漏洞
CVE-2024-38662Linux kernel 安全漏洞
CVE-2024-38780Linux kernel 安全漏洞
CVE-2024-39277Linux kernel 安全漏洞
CVE-2024-34777Linux kernel 安全漏洞
CVE-2024-36288Linux kernel 安全漏洞
CVE-2024-36477Linux kernel 安全漏洞
CVE-2024-36481Linux kernel 安全漏洞

显示前 20 条,共 40 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-36244

暂无评论


发表评论