目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-42071— Linux kernel 安全漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于在非 NAPI softirq 上下文中调用 napi_consume_skb 时没有使用预算为 0,这可能导致在不安全的上下文中调用该函数。

CVSS 7.8 · High EPSS 0.22% · P11

影响版本矩阵 6

厂商产品 版本范围状态
Linux Linux 386e69865311044b576ff536c99c6ee9cc98a228< ef7646ed49fff962e97b276f4ab91327a67eeb5a affected
386e69865311044b576ff536c99c6ee9cc98a228< 84b767f9e34fdb143c09e66a2a20722fc2921821 affected
6.9 affected
< 6.9 unaffected
6.9.8≤ 6.9.* unaffected
6.10≤ * unaffected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-42071 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
ionic: use dev_consume_skb_any outside of napi
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ionic: use dev_consume_skb_any outside of napi If we're not in a NAPI softirq context, we need to be careful about how we call napi_consume_skb(), specifically we need to call it with budget==0 to signal to it that we're not in a safe context. This was found while running some configuration stress testing of traffic and a change queue config loop running, and this curious note popped out: [ 4371.402645] BUG: using smp_processor_id() in preemptible [00000000] code: ethtool/20545 [ 4371.402897] caller is napi_skb_cache_put+0x16/0x80 [ 4371.403120] CPU: 25 PID: 20545 Comm: ethtool Kdump: loaded Tainted: G OE 6.10.0-rc3-netnext+ #8 [ 4371.403302] Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 01/23/2021 [ 4371.403460] Call Trace: [ 4371.403613] <TASK> [ 4371.403758] dump_stack_lvl+0x4f/0x70 [ 4371.403904] check_preemption_disabled+0xc1/0xe0 [ 4371.404051] napi_skb_cache_put+0x16/0x80 [ 4371.404199] ionic_tx_clean+0x18a/0x240 [ionic] [ 4371.404354] ionic_tx_cq_service+0xc4/0x200 [ionic] [ 4371.404505] ionic_tx_flush+0x15/0x70 [ionic] [ 4371.404653] ? ionic_lif_qcq_deinit.isra.23+0x5b/0x70 [ionic] [ 4371.404805] ionic_txrx_deinit+0x71/0x190 [ionic] [ 4371.404956] ionic_reconfigure_queues+0x5f5/0xff0 [ionic] [ 4371.405111] ionic_set_ringparam+0x2e8/0x3e0 [ionic] [ 4371.405265] ethnl_set_rings+0x1f1/0x300 [ 4371.405418] ethnl_default_set_doit+0xbb/0x160 [ 4371.405571] genl_family_rcv_msg_doit+0xff/0x130 [...] I found that ionic_tx_clean() calls napi_consume_skb() which calls napi_skb_cache_put(), but before that last call is the note /* Zero budget indicate non-NAPI context called us, like netpoll */ and DEBUG_NET_WARN_ON_ONCE(!in_softirq()); Those are pretty big hints that we're doing it wrong. We can pass a context hint down through the calls to let ionic_tx_clean() know what we're doing so it can call napi_consume_skb() correctly.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于在非 NAPI softirq 上下文中调用 napi_consume_skb 时没有使用预算为 0,这可能导致在不安全的上下文中调用该函数。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 386e69865311044b576ff536c99c6ee9cc98a228 ~ ef7646ed49fff962e97b276f4ab91327a67eeb5a -
Linux Linux 6.9 -

二、漏洞 CVE-2024-42071 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-42071 的情报信息

请登录查看更多情报信息。

CVE-2024-42071 其他参考 (2)

同批安全公告 · Linux · 2024-07-29 · 共 121 条

CVE-2024-41081 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2024-41073 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2024-41040 9.8 CRITICAL Linux kernel 安全漏洞
CVE-2024-41091 8.8 HIGH Linux kernel 安全漏洞
CVE-2024-42083 8.8 HIGH Linux kernel 安全漏洞
CVE-2024-41062 8.8 HIGH Linux kernel 安全漏洞
CVE-2024-41046 8.8 HIGH Linux kernel 安全漏洞
CVE-2024-41090 8.8 HIGH Linux kernel 安全漏洞
CVE-2024-41057 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-41041 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-42064 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-41017 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-42066 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-41049 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-41051 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-42067 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-42068 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-42069 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-41069 7.8 HIGH Linux kernel 安全漏洞
CVE-2024-42075 7.8 HIGH Linux kernel 安全漏洞

显示前 20 条,共 121 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-42071

暂无评论


发表评论