目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-38586— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 中等 EPSS 0.25% · P17

可能的 ATT&CK 技术 1AI

T1499 · Endpoint Denial of Service

影响版本矩阵 16

厂商产品版本范围状态
LinuxLinux9020845fb5d6bb4876a38fdf1259600e7d9a63d4< 61c1c98e2607120ce9c3fa1bf75e6da909712b27affected
9020845fb5d6bb4876a38fdf1259600e7d9a63d4< b6d21cf40de103d63ae78551098a7c06af8c98ddaffected
9020845fb5d6bb4876a38fdf1259600e7d9a63d4< 0c48185a95309556725f818b82120bb74e9c627daffected
9020845fb5d6bb4876a38fdf1259600e7d9a63d4< 68222d7b4b72aa321135cd453dac37f00ec41fd1affected
9020845fb5d6bb4876a38fdf1259600e7d9a63d4< 078d5b7500d70af2de6b38e226b03f0b932026a6affected
9020845fb5d6bb4876a38fdf1259600e7d9a63d4< 54e7a0d111240c92c0f02ceba6eb8f26bf6d6479affected
9020845fb5d6bb4876a38fdf1259600e7d9a63d4< c71e3a5cffd5309d7f84444df03d5b72600cc417affected
5.7affected
… +8 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-38586 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
r8169: Fix possible ring buffer corruption on fragmented Tx packets.
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: r8169: Fix possible ring buffer corruption on fragmented Tx packets. An issue was found on the RTL8125b when transmitting small fragmented packets, whereby invalid entries were inserted into the transmit ring buffer, subsequently leading to calls to dma_unmap_single() with a null address. This was caused by rtl8169_start_xmit() not noticing changes to nr_frags which may occur when small packets are padded (to work around hardware quirks) in rtl8169_tso_csum_v2(). To fix this, postpone inspecting nr_frags until after any padding has been applied.
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于r8169 中存在缓冲区损坏问题。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 9020845fb5d6bb4876a38fdf1259600e7d9a63d4 ~ 61c1c98e2607120ce9c3fa1bf75e6da909712b27 -
LinuxLinux 5.7 -

二、漏洞 CVE-2024-38586 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-38586 的情报信息

登录查看更多情报信息。

CVE-2024-38586 其他参考 (7)

同批安全公告 · Linux · 2024-06-19 · 共 122 条

CVE-2024-38611Linux kernel 安全漏洞
CVE-2021-47585Linux kernel安全漏洞
CVE-2021-47584Linux kernel 安全漏洞
CVE-2021-47582Linux kernel 安全漏洞
CVE-2021-47583Linux kernel 安全漏洞
CVE-2021-47579Linux kernel 安全漏洞
CVE-2021-47580Linux kernel 安全漏洞
CVE-2021-47578Linux kernel 安全漏洞
CVE-2021-47576Linux kernel安全漏洞
CVE-2021-47577Linux kernel 安全漏洞
CVE-2024-38617Linux kernel 安全漏洞
CVE-2024-38618Linux kernel 安全漏洞
CVE-2024-38616Linux kernel 安全漏洞
CVE-2024-38615Linux kernel 安全漏洞
CVE-2024-38614Linux kernel安全漏洞
CVE-2024-38613Linux kernel安全漏洞
CVE-2024-38602Linux kernel 安全漏洞
CVE-2024-38603Linux kernel 安全漏洞
CVE-2024-38601Linux kernel 安全漏洞
CVE-2024-38604Linux kernel 安全漏洞

显示前 20 条,共 122 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-38586

暂无评论


发表评论