Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-36281— net/mlx5: Use mlx5_ipsec_rx_status_destroy to correctly delete status rules

AI Predicted 6.5 Difficulty: Moderate EPSS 0.24% · P16

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 9

VendorProductVersion RangeStatus
LinuxLinux20af7afcd8b85a4cb413072d631bf9a6469eee3a< b0a15cde37a8388e57573686f650a17208ae1212affected
94af50c0a9bb961fe93cf0fdd14eb0883da86721< cc9ac559f2e21894c21ac5b0c85fb24a5cab266caffected
94af50c0a9bb961fe93cf0fdd14eb0883da86721< 16d66a4fa81da07bc4ed19f4e53b87263c2f8d38affected
6.6.8< 6.6.33affected
6.7affected
< 6.7unaffected
6.6.33≤ 6.6.*unaffected
6.9.4≤ 6.9.*unaffected
… +1 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-36281

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net/mlx5: Use mlx5_ipsec_rx_status_destroy to correctly delete status rules
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Use mlx5_ipsec_rx_status_destroy to correctly delete status rules rx_create no longer allocates a modify_hdr instance that needs to be cleaned up. The mlx5_modify_header_dealloc call will lead to a NULL pointer dereference. A leak in the rules also previously occurred since there are now two rules populated related to status. BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 109907067 P4D 109907067 PUD 116890067 PMD 0 Oops: 0000 [#1] SMP CPU: 1 PID: 484 Comm: ip Not tainted 6.9.0-rc2-rrameshbabu+ #254 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS Arch Linux 1.16.3-1-1 04/01/2014 RIP: 0010:mlx5_modify_header_dealloc+0xd/0x70 <snip> Call Trace: <TASK> ? show_regs+0x60/0x70 ? __die+0x24/0x70 ? page_fault_oops+0x15f/0x430 ? free_to_partial_list.constprop.0+0x79/0x150 ? do_user_addr_fault+0x2c9/0x5c0 ? exc_page_fault+0x63/0x110 ? asm_exc_page_fault+0x27/0x30 ? mlx5_modify_header_dealloc+0xd/0x70 rx_create+0x374/0x590 rx_add_rule+0x3ad/0x500 ? rx_add_rule+0x3ad/0x500 ? mlx5_cmd_exec+0x2c/0x40 ? mlx5_create_ipsec_obj+0xd6/0x200 mlx5e_accel_ipsec_fs_add_rule+0x31/0xf0 mlx5e_xfrm_add_state+0x426/0xc00 <snip>
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于net/mlx5模块存在问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 20af7afcd8b85a4cb413072d631bf9a6469eee3a ~ b0a15cde37a8388e57573686f650a17208ae1212 -
LinuxLinux 6.7 -

II. Public POCs for CVE-2024-36281

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-36281

登录查看更多情报信息。

Other References for CVE-2024-36281 (3)

Same Patch Batch · Linux · 2024-06-21 · 40 CVEs total

CVE-2024-362889.8 CRITICALSUNRPC: Fix loop termination condition in gss_free_in_token_pages()
CVE-2024-383818.8 HIGHnfc: nci: Fix uninit-value in nci_rx_work
CVE-2024-336197.8 HIGHefi: libstub: only free priv.runtime_map when allocated
CVE-2024-364777.8 HIGHtpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer
CVE-2024-386287.8 HIGHusb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.
CVE-2024-362867.8 HIGHnetfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
CVE-2024-386267.8 HIGHfuse: clear FR_SENT when re-adding requests into pending list
CVE-2024-383887.8 HIGHALSA: hda/cs_dsp_ctl: Use private_free for control cleanup
CVE-2024-386237.8 HIGHfs/ntfs3: Use variable length array instead of fixed size
CVE-2024-386357.8 HIGHsoundwire: cadence: fix invalid PDI offset
CVE-2024-386597.3 HIGHenic: Validate length of nl attributes in enic_set_vf_port
CVE-2024-38631iio: adc: PAC1934: fix accessing out of bounds array index
CVE-2024-38625fs/ntfs3: Check 'folio' pointer for NULL
CVE-2024-38632vfio/pci: fix potential memory leak in vfio_intx_enable()
CVE-2024-38633serial: max3100: Update uart_driver_registered on driver removal
CVE-2024-38634serial: max3100: Lock port->lock when calling uart_handle_cts_change()
CVE-2024-38636f2fs: multidev: fix to recognize valid zero block address
CVE-2024-38637greybus: lights: check return of get_channel_from_mode
CVE-2024-38662bpf: Allow delete from sockmap/sockhash only if update is allowed
CVE-2024-38780dma-buf/sw-sync: don't enable IRQ from sync_print_obj()

Showing top 20 of 40 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-36281

No comments yet


Leave a comment