目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-36952— Linux kernel 安全漏洞

AI 预测 5.3 利用难度: 中等 EPSS 0.22% · P13

可能的 ATT&CK 技术 1AI

T1059.004 · Unix Shell

影响版本矩阵 12

厂商产品版本范围状态
LinuxLinux92d7f7b0cde3ad2260e7462b40867b57efd49851< f2c7f029051edc4b394bb48edbe2297575abefe0affected
92d7f7b0cde3ad2260e7462b40867b57efd49851< 0936809d968ecf81e0726fbd02ff2a5732d960c3affected
92d7f7b0cde3ad2260e7462b40867b57efd49851< 76337eb8daee32bcc67742efab3168ed4ca299d0affected
92d7f7b0cde3ad2260e7462b40867b57efd49851< 718602cd15f4c5710850090ea3066a89eeb46278affected
92d7f7b0cde3ad2260e7462b40867b57efd49851< 4ddf01f2f1504fa08b766e8cfeec558e9f8eef6caffected
2.6.23affected
< 2.6.23unaffected
5.15.159≤ 5.15.*unaffected
… +4 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-36952 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
scsi: lpfc: Move NPIV's transport unregistration to after resource clean up
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Move NPIV's transport unregistration to after resource clean up There are cases after NPIV deletion where the fabric switch still believes the NPIV is logged into the fabric. This occurs when a vport is unregistered before the Remove All DA_ID CT and LOGO ELS are sent to the fabric. Currently fc_remove_host(), which calls dev_loss_tmo for all D_IDs including the fabric D_ID, removes the last ndlp reference and frees the ndlp rport object. This sometimes causes the race condition where the final DA_ID and LOGO are skipped from being sent to the fabric switch. Fix by moving the fc_remove_host() and scsi_remove_host() calls after DA_ID and LOGO are sent.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于 scsi:lpfc 模块将 NPIV 的传输取消注册移至资源清理之后。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 92d7f7b0cde3ad2260e7462b40867b57efd49851 ~ f2c7f029051edc4b394bb48edbe2297575abefe0 -
LinuxLinux 2.6.23 -

二、漏洞 CVE-2024-36952 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-36952 的情报信息

登录查看更多情报信息。

CVE-2024-36952 其他参考 (5)

同批安全公告 · Linux · 2024-05-30 · 共 93 条

CVE-2024-369589.8 CRITICALLinux kernel 安全漏洞
CVE-2024-368869.8 CRITICALLinux kernel 安全漏洞
CVE-2024-369119.8 CRITICALLinux kernel 安全漏洞
CVE-2024-369129.6 CRITICALLinux kernel 安全漏洞
CVE-2024-369139.3 CRITICALLinux kernel 安全漏洞
CVE-2024-369099.3 CRITICALLinux kernel 安全漏洞
CVE-2024-369228.8 HIGHLinux kernel 安全漏洞
CVE-2024-369218.8 HIGHLinux kernel 安全漏洞
CVE-2024-369108.4 HIGHLinux kernel 安全漏洞
CVE-2024-360328.1 HIGHLinux kernel安全漏洞
CVE-2024-369337.8 HIGHLinux kernel 安全漏洞
CVE-2024-369047.8 HIGHLinux kernel 安全漏洞
CVE-2024-369147.8 HIGHLinux kernel 安全漏洞
CVE-2024-369187.8 HIGHLinux kernel 安全漏洞
CVE-2024-360187.8 HIGHLinux kernel 安全漏洞
CVE-2024-368947.8 HIGHLinux kernel 安全漏洞
CVE-2024-368907.8 HIGHLinux kernel 安全漏洞
CVE-2024-369407.8 HIGHLinux kernel 安全漏洞
CVE-2024-369287.8 HIGHLinux kernel 安全漏洞
CVE-2024-368847.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 93 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-36952

暂无评论


发表评论