目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-38601— Linux kernel 安全漏洞

AI 预测 6.5 利用难度: 中等 EPSS 0.18% · P7

可能的 ATT&CK 技术 1AI

T1014 · Rootkit

影响版本矩阵 20

厂商产品版本范围状态
LinuxLinux659f451ff21315ebfeeb46b9adccee8ce1b52c25< b50932ea673b5a089a4bb570a8a868d95c72854eaffected
659f451ff21315ebfeeb46b9adccee8ce1b52c25< c68b7a442ee61d04ca58b2b5cb5ea7cb8230f84aaffected
659f451ff21315ebfeeb46b9adccee8ce1b52c25< 1e160196042cac946798ac192a0bc3398f1aa66baffected
659f451ff21315ebfeeb46b9adccee8ce1b52c25< 595363182f28786d641666a09e674b852c83b4bbaffected
659f451ff21315ebfeeb46b9adccee8ce1b52c25< 54c64967ba5f8658ae7da76005024ebd3d9d8f6eaffected
659f451ff21315ebfeeb46b9adccee8ce1b52c25< af3274905b3143ea23142bbf77bd9b610c54e533affected
659f451ff21315ebfeeb46b9adccee8ce1b52c25< 5ef9e330406d3fb4f4b2c8bca2c6b8a93bae32d1affected
659f451ff21315ebfeeb46b9adccee8ce1b52c25< 79b52013429a42b8efdb0cda8bb0041386abab87affected
… +12 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-38601 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ring-buffer: Fix a race between readers and resize checks
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix a race between readers and resize checks The reader code in rb_get_reader_page() swaps a new reader page into the ring buffer by doing cmpxchg on old->list.prev->next to point it to the new page. Following that, if the operation is successful, old->list.next->prev gets updated too. This means the underlying doubly-linked list is temporarily inconsistent, page->prev->next or page->next->prev might not be equal back to page for some page in the ring buffer. The resize operation in ring_buffer_resize() can be invoked in parallel. It calls rb_check_pages() which can detect the described inconsistency and stop further tracing: [ 190.271762] ------------[ cut here ]------------ [ 190.271771] WARNING: CPU: 1 PID: 6186 at kernel/trace/ring_buffer.c:1467 rb_check_pages.isra.0+0x6a/0xa0 [ 190.271789] Modules linked in: [...] [ 190.271991] Unloaded tainted modules: intel_uncore_frequency(E):1 skx_edac(E):1 [ 190.272002] CPU: 1 PID: 6186 Comm: cmd.sh Kdump: loaded Tainted: G E 6.9.0-rc6-default #5 158d3e1e6d0b091c34c3b96bfd99a1c58306d79f [ 190.272011] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.0-0-gd239552c-rebuilt.opensuse.org 04/01/2014 [ 190.272015] RIP: 0010:rb_check_pages.isra.0+0x6a/0xa0 [ 190.272023] Code: [...] [ 190.272028] RSP: 0018:ffff9c37463abb70 EFLAGS: 00010206 [ 190.272034] RAX: ffff8eba04b6cb80 RBX: 0000000000000007 RCX: ffff8eba01f13d80 [ 190.272038] RDX: ffff8eba01f130c0 RSI: ffff8eba04b6cd00 RDI: ffff8eba0004c700 [ 190.272042] RBP: ffff8eba0004c700 R08: 0000000000010002 R09: 0000000000000000 [ 190.272045] R10: 00000000ffff7f52 R11: ffff8eba7f600000 R12: ffff8eba0004c720 [ 190.272049] R13: ffff8eba00223a00 R14: 0000000000000008 R15: ffff8eba067a8000 [ 190.272053] FS: 00007f1bd64752c0(0000) GS:ffff8eba7f680000(0000) knlGS:0000000000000000 [ 190.272057] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 190.272061] CR2: 00007f1bd6662590 CR3: 000000010291e001 CR4: 0000000000370ef0 [ 190.272070] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 [ 190.272073] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 [ 190.272077] Call Trace: [ 190.272098] <TASK> [ 190.272189] ring_buffer_resize+0x2ab/0x460 [ 190.272199] __tracing_resize_ring_buffer.part.0+0x23/0xa0 [ 190.272206] tracing_resize_ring_buffer+0x65/0x90 [ 190.272216] tracing_entries_write+0x74/0xc0 [ 190.272225] vfs_write+0xf5/0x420 [ 190.272248] ksys_write+0x67/0xe0 [ 190.272256] do_syscall_64+0x82/0x170 [ 190.272363] entry_SYSCALL_64_after_hwframe+0x76/0x7e [ 190.272373] RIP: 0033:0x7f1bd657d263 [ 190.272381] Code: [...] [ 190.272385] RSP: 002b:00007ffe72b643f8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001 [ 190.272391] RAX: ffffffffffffffda RBX: 0000000000000002 RCX: 00007f1bd657d263 [ 190.272395] RDX: 0000000000000002 RSI: 0000555a6eb538e0 RDI: 0000000000000001 [ 190.272398] RBP: 0000555a6eb538e0 R08: 000000000000000a R09: 0000000000000000 [ 190.272401] R10: 0000555a6eb55190 R11: 0000000000000246 R12: 00007f1bd6662500 [ 190.272404] R13: 0000000000000002 R14: 00007f1bd6667c00 R15: 0000000000000002 [ 190.272412] </TASK> [ 190.272414] ---[ end trace 0000000000000000 ]--- Note that ring_buffer_resize() calls rb_check_pages() only if the parent trace_buffer has recording disabled. Recent commit d78ab792705c ("tracing: Stop current tracer when resizing buffer") causes that it is now always the case which makes it more likely to experience this issue. The window to hit this race is nonetheless very small. To help reproducing it, one can add a delay loop in rb_get_reader_page(): ret = rb_head_page_replace(reader, cpu_buffer->reader_page); if (!ret) goto spin; for (unsigned i = 0; i < 1U << 26; i++) /* inserted delay loop */ __asm__ __volatile__ ("" : : : "memory"); rb_list_head(reader->list.next)->prev = &cpu_buffer->reader_page->list; .. ---truncated---
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于读取器和调整大小检查之间存在竞争。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 659f451ff21315ebfeeb46b9adccee8ce1b52c25 ~ b50932ea673b5a089a4bb570a8a868d95c72854e -
LinuxLinux 3.5 -

二、漏洞 CVE-2024-38601 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-38601 的情报信息

登录查看更多情报信息。

CVE-2024-38601 邮件列表归档 (1)

CVE-2024-38601 其他参考 (9)

同批安全公告 · Linux · 2024-06-19 · 共 122 条

CVE-2024-3855810.0 CRITICALLinux kernel 安全漏洞
CVE-2024-385709.8 CRITICALLinux kernel 安全漏洞
CVE-2021-475879.8 CRITICALLinux kernel 安全漏洞
CVE-2024-385449.8 CRITICALLinux kernel 安全漏洞
CVE-2021-476118.1 HIGHLinux kernel 安全漏洞
CVE-2024-385877.8 HIGHLinux kernel 安全漏洞
CVE-2024-385567.8 HIGHLinux kernel 安全漏洞
CVE-2024-386107.8 HIGHLinux kernel 安全漏洞
CVE-2024-386057.8 HIGHLinux kernel 安全漏洞
CVE-2024-385997.8 HIGHLinux kernel 安全漏洞
CVE-2024-385927.8 HIGHLinux kernel安全漏洞
CVE-2024-385647.8 HIGHLinux kernel 安全漏洞
CVE-2024-385687.8 HIGHLinux kernel 安全漏洞
CVE-2024-385727.8 HIGHLinux kernel安全漏洞
CVE-2024-385787.8 HIGHLinux kernel 安全漏洞
CVE-2024-385807.8 HIGHLinux kernel 安全漏洞
CVE-2024-385697.8 HIGHLinux kernel 安全漏洞
CVE-2024-385837.8 HIGHLinux kernel 安全漏洞
CVE-2024-386147.8 HIGHLinux kernel安全漏洞
CVE-2024-385887.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 122 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-38601

暂无评论


发表评论