目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-38581— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.23% · P14

Affected Version Matrix 10

ベンダープロダクトVersion Rangeステータス
LinuxLinux8c5e13ec6a2c26d31d0551dc382661dc10823be0< 70b1bf6d9edc8692d241f59a65f073aec6d501deaffected
8c5e13ec6a2c26d31d0551dc382661dc10823be0< 39cfce75168c11421d70b8c0c65f6133edccb82aaffected
8c5e13ec6a2c26d31d0551dc382661dc10823be0< 0f98c144c15c8fc0f3176c994bd4e727ef718a5caffected
8c5e13ec6a2c26d31d0551dc382661dc10823be0< 948255282074d9367e01908b3f5dcf8c10fc9c3daffected
4.20affected
< 4.20unaffected
6.1.93≤ 6.1.*unaffected
6.6.33≤ 6.6.*unaffected
… +2 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-38581の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
drm/amdgpu/mes: fix use-after-free issue
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/mes: fix use-after-free issue Delete fence fallback timer to fix the ramdom use-after-free issue. v2: move to amdgpu_mes.c
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于drm/amdgpu/mes 中存在释放后重用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 8c5e13ec6a2c26d31d0551dc382661dc10823be0 ~ 70b1bf6d9edc8692d241f59a65f073aec6d501de -
LinuxLinux 4.20 -

II. CVE-2024-38581の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-38581のインテリジェンス情報

登录查看更多情报信息。

CVE-2024-38581 其他参考 (4)

Same Patch Batch · Linux · 2024-06-19 · 122 CVEs total

CVE-2024-3855810.0 CRITICALnet: openvswitch: fix overwriting ct original tuple for ICMPv6
CVE-2024-385709.8 CRITICALgfs2: Fix potential glock use-after-free on unmount
CVE-2021-475879.8 CRITICALnet: systemport: Add global locking for descriptor lifecycle
CVE-2024-385449.8 CRITICALRDMA/rxe: Fix seg fault in rxe_comp_queue_pkt
CVE-2021-476118.1 HIGHmac80211: validate extended element ID is present
CVE-2024-385887.8 HIGHftrace: Fix possible use-after-free issue in ftrace_location()
CVE-2024-385567.8 HIGHnet/mlx5: Add a timeout to acquire the command queue semaphore
CVE-2024-386107.8 HIGHdrivers/virt/acrn: fix PFNMAP PTE checks in acrn_vm_ram_map()
CVE-2024-386057.8 HIGHALSA: core: Fix NULL module pointer assignment at card init
CVE-2024-385997.8 HIGHjffs2: prevent xattr node from overflowing the eraseblock
CVE-2024-385927.8 HIGHdrm/mediatek: Init `ddp_comp` with devm_kcalloc()
CVE-2024-385647.8 HIGHbpf: Add BPF_PROG_TYPE_CGROUP_SKB attach type enforcement in BPF_LINK_CREATE
CVE-2024-385687.8 HIGHdrivers/perf: hisi: hns3: Fix out-of-bound access when valid event group
CVE-2024-385727.8 HIGHwifi: ath12k: fix out-of-bound access of qmi_invoke_handler()
CVE-2024-385787.8 HIGHecryptfs: Fix buffer size for tag 66 packet
CVE-2024-385697.8 HIGHdrivers/perf: hisi_pcie: Fix out-of-bound access when valid event group
CVE-2024-385837.8 HIGHnilfs2: fix use-after-free of timer for log writer thread
CVE-2024-385877.8 HIGHspeakup: Fix sizeof() vs ARRAY_SIZE() bug
CVE-2021-475777.8 HIGHio-wq: check for wq exit after adding new worker task_work
CVE-2024-385807.8 HIGHepoll: be better about file lifetimes

Showing 20 of 122 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2024-38581へのコメント

まだコメントはありません


コメントを残す