Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-41081— ila: block BH in ila_output()

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在ila_output函数中,需要在调用net/core/dst_cache.c帮助函数之前禁用BH。

CVSS 9.8 · Critical EPSS 0.87% · P57

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5< 7435bd2f84a25aba607030237261b3795ba782da affected
79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5< 96103371091c6476eb07f4c66624bdd1b42f758a affected
79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5< a0cafb7b0b94d18e4813ee4b712a056f280e7b5a affected
79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5< feac2391e26b086f73be30e9b1ab215eada8d830 affected
79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5< b4eb25a3d70df925a9fa4e82d17a958a0a228f5f affected
79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5< 522c3336c2025818fa05e9daf0ac35711e55e316 affected
79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5< 9f9c79d8e527d867e0875868b14fb76e6011e70c affected
79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5< cf28ff8e4c02e1ffa850755288ac954b6ff0db8c affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2024-41081

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ila: block BH in ila_output()
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ila: block BH in ila_output() As explained in commit 1378817486d6 ("tipc: block BH before using dst_cache"), net/core/dst_cache.c helpers need to be called with BH disabled. ila_output() is called from lwtunnel_output() possibly from process context, and under rcu_read_lock(). We might be interrupted by a softirq, re-enter ila_output() and corrupt dst_cache data structures. Fix the race by using local_bh_disable().
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在ila_output函数中,需要在调用net/core/dst_cache.c帮助函数之前禁用BH。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 79ff2fc31e0f6a52eeb67fb89fba87e822b9b7b5 ~ 7435bd2f84a25aba607030237261b3795ba782da -
Linux Linux 4.10 -

II. Public POCs for CVE-2024-41081

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-41081

请登录查看更多情报信息。

Other References for CVE-2024-41081 (8)

Same Patch Batch · Linux · 2024-07-29 · 121 CVEs total

CVE-2024-41073 9.8 CRITICAL nvme: avoid double free special payload
CVE-2024-41040 9.8 CRITICAL net/sched: Fix UAF when resolving a clash
CVE-2024-41091 8.8 HIGH tun: add missing verification for short frame
CVE-2024-42083 8.8 HIGH ionic: fix kernel panic due to multi-buffer handling
CVE-2024-41062 8.8 HIGH bluetooth/l2cap: sync sock recv cb and release
CVE-2024-41046 8.8 HIGH net: ethernet: lantiq_etop: fix double free in detach
CVE-2024-41090 8.8 HIGH tap: add missing verification for short frame
CVE-2024-42069 7.8 HIGH net: mana: Fix possible double free in error handling path
CVE-2024-41041 7.8 HIGH udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port().
CVE-2024-42064 7.8 HIGH drm/amd/display: Skip pipe if the pipe idx not set properly
CVE-2024-41045 7.8 HIGH bpf: Defer work in bpf_timer_cancel_and_free
CVE-2024-41015 7.8 HIGH ocfs2: add bounds checking to ocfs2_check_dir_entry()
CVE-2024-42066 7.8 HIGH drm/xe: Fix potential integer overflow in page size calculation
CVE-2024-41049 7.8 HIGH filelock: fix potential use-after-free in posix_lock_inode
CVE-2024-41051 7.8 HIGH cachefiles: wait for ondemand_object_worker to finish when dropping object
CVE-2024-42067 7.8 HIGH bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()
CVE-2024-42068 7.8 HIGH bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro()
CVE-2024-42072 7.8 HIGH bpf: Fix may_goto with negative offset.
CVE-2024-41064 7.8 HIGH powerpc/eeh: avoid possible crash when edev->pdev changes
CVE-2024-42075 7.8 HIGH bpf: Fix remap of arena.

Showing top 20 of 121 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-41081

No comments yet


Leave a comment