Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-38554— ax25: Fix reference count leak issue of net_device

AI Predicted 5.5 Difficulty: Hard EPSS 0.24% · P15

Possible ATT&CK Techniques 1AI

T1496 · Resource Hijacking

Affected Version Matrix 22

VendorProductVersion RangeStatus
LinuxLinuxd01ffb9eee4af165d83b08dd73ebdf9fe94a519b< 3ec437f9bbae68e9b38115c4c91de995f73f6badaffected
d01ffb9eee4af165d83b08dd73ebdf9fe94a519b< 965d940fb7414b310a22666503d2af69459c981baffected
d01ffb9eee4af165d83b08dd73ebdf9fe94a519b< 8bad3a20a27be8d935f2aae08d3c6e743754944aaffected
d01ffb9eee4af165d83b08dd73ebdf9fe94a519b< eef95df9b752699bddecefa851f64858247246e9affected
d01ffb9eee4af165d83b08dd73ebdf9fe94a519b< 36e56b1b002bb26440403053f19f9e1a8bc075b2affected
ef0a2a0565727a48f2e36a2c461f8b1e3a61922daffected
e2b558fe507a1ed4c43db2b0057fc6e41f20a14caffected
418993bbaafb0cd48f904ba68eeda052d624c821affected
… +14 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-38554

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ax25: Fix reference count leak issue of net_device
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ax25: Fix reference count leak issue of net_device There is a reference count leak issue of the object "net_device" in ax25_dev_device_down(). When the ax25 device is shutting down, the ax25_dev_device_down() drops the reference count of net_device one or zero times depending on if we goto unlock_put or not, which will cause memory leak. In order to solve the above issue, decrease the reference count of net_device after dev->ax25_ptr is set to null.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于net_device存在引用计数泄漏问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux d01ffb9eee4af165d83b08dd73ebdf9fe94a519b ~ 3ec437f9bbae68e9b38115c4c91de995f73f6bad -
LinuxLinux 5.17 -

II. Public POCs for CVE-2024-38554

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-38554

登录查看更多情报信息。

Other References for CVE-2024-38554 (4)

Same Patch Batch · Linux · 2024-06-19 · 122 CVEs total

CVE-2024-3855810.0 CRITICALnet: openvswitch: fix overwriting ct original tuple for ICMPv6
CVE-2021-475879.8 CRITICALnet: systemport: Add global locking for descriptor lifecycle
CVE-2024-385709.8 CRITICALgfs2: Fix potential glock use-after-free on unmount
CVE-2024-385449.8 CRITICALRDMA/rxe: Fix seg fault in rxe_comp_queue_pkt
CVE-2021-476118.1 HIGHmac80211: validate extended element ID is present
CVE-2024-385877.8 HIGHspeakup: Fix sizeof() vs ARRAY_SIZE() bug
CVE-2024-386107.8 HIGHdrivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()
CVE-2024-386057.8 HIGHALSA: core: Fix NULL module pointer assignment at card init
CVE-2024-385997.8 HIGHjffs2: prevent xattr node from overflowing the eraseblock
CVE-2024-385647.8 HIGHbpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE
CVE-2024-385927.8 HIGHdrm/mediatek: Init `ddp_comp` with devm_kcalloc()
CVE-2024-385887.8 HIGHftrace: Fix possible use-after-free issue in ftrace_location()
CVE-2024-385817.8 HIGHdrm/amdgpu/mes: fix use-after-free issue
CVE-2024-385787.8 HIGHecryptfs: Fix buffer size for tag 66 packet
CVE-2024-385727.8 HIGHwifi: ath12k: fix out-of-bound access of qmi_invoke_handler()
CVE-2024-385807.8 HIGHepoll: be better about file lifetimes
CVE-2024-385687.8 HIGHdrivers/perf: hisi: hns3: Fix out-of-bound access when valid event group
CVE-2024-385837.8 HIGHnilfs2: fix use-after-free of timer for log writer thread
CVE-2024-386147.8 HIGHopenrisc: traps: Don't send signals to kernel mode threads
CVE-2024-385697.8 HIGHdrivers/perf: hisi_pcie: Fix out-of-bound access when valid event group

Showing top 20 of 122 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-38554

No comments yet


Leave a comment