Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-36288— SUNRPC: Fix loop termination condition in gss_free_in_token_pages()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于SUNRPC模块gss_free_in_token_pages中的循环终止条件存在问题。

CVSS 9.8 · Critical EPSS 0.75% · P52

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux ab8466d4e26806a4ae82c282762c4545eecf45ef< 57ff6c0a175930856213b2aa39f8c845a53e5b1c affected
4420b73c7f26fd5fcb37bbce5313dd356ef1b3ca< 6ed45d20d30005bed94c8c527ce51d5ad8121018 affected
f148a95f68c66c1b097391b68e153d5a46f0e780< 4cefcd0af7458bdeff56a9d8dfc6868ce23d128a affected
fe0b474974fee7af1df286e0edd5a1460c811865< b4878ea99f2b40ef1925720b1b4ca7f4af1ba785 affected
c1d8c429e4d2ce85ec5c92cf71cb419baf75c56f< af628d43a822b78ad8d4a58d8259f8bf8bc71115 affected
8ca148915670a2921afcc255af9e1dc80f37b052< 0a1cb0c6102bb4fd310243588d39461da49497ad affected
bafa6b4d95d97877baa61883ff90f7e374427fae< 4a77c3dead97339478c7422eb07bf4bf63577008 affected
a3c1afd5d7ad59e34a275d80c428952f83c8c1f0 affected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-36288

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix loop termination condition in gss_free_in_token_pages() The in_token->pages[] array is not NULL terminated. This results in the following KASAN splat: KASAN: maybe wild-memory-access in range [0x04a2013400000008-0x04a201340000000f]
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于SUNRPC模块gss_free_in_token_pages中的循环终止条件存在问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux ab8466d4e26806a4ae82c282762c4545eecf45ef ~ 57ff6c0a175930856213b2aa39f8c845a53e5b1c -
Linux Linux 6.9.3 ~ 6.9.4 -

II. Public POCs for CVE-2024-36288

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-36288

登录查看更多情报信息。

Mailing List Discussions for CVE-2024-36288 (1)

Other References for CVE-2024-36288 (8)

Same Patch Batch · Linux · 2024-06-21 · 40 CVEs total

CVE-2024-38381 8.8 HIGH nfc: nci: Fix uninit-value in nci_rx_work
CVE-2024-38628 7.8 HIGH usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.
CVE-2024-38626 7.8 HIGH fuse: clear FR_SENT when re-adding requests into pending list
CVE-2024-38623 7.8 HIGH fs/ntfs3: Use variable length array instead of fixed size
CVE-2024-38635 7.8 HIGH soundwire: cadence: fix invalid PDI offset
CVE-2024-38388 7.8 HIGH ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup
CVE-2024-36286 7.8 HIGH netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu()
CVE-2024-36477 7.8 HIGH tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer
CVE-2024-33619 7.8 HIGH efi: libstub: only free priv.runtime_map when allocated
CVE-2024-38659 7.3 HIGH enic: Validate length of nl attributes in enic_set_vf_port
CVE-2024-38780 dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
CVE-2024-38662 bpf: Allow delete from sockmap/sockhash only if update is allowed
CVE-2024-38637 greybus: lights: check return of get_channel_from_mode
CVE-2024-39277 dma-mapping: benchmark: handle NUMA_NO_NODE correctly
CVE-2024-38636 f2fs: multidev: fix to recognize valid zero block address
CVE-2024-34777 dma-mapping: benchmark: fix node id validation
CVE-2024-38634 serial: max3100: Lock port->lock when calling uart_handle_cts_change()
CVE-2024-38633 serial: max3100: Update uart_driver_registered on driver removal
CVE-2024-38632 vfio/pci: fix potential memory leak in vfio_intx_enable()
CVE-2024-31076 genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline

Showing top 20 of 40 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-36288

No comments yet


Leave a comment