Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在bpf arena 逻辑没有考虑到 mremap 操作,需要为多次 mmap 事件添加引用计数,以防止 arena_vm_close 中的释放后重用问题。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 317460317a02a1af512697e6e964298dedd8a163< 87496a1b01e8e2e399428c0db25e106f7961d01e |
affected |
317460317a02a1af512697e6e964298dedd8a163< b90d77e5fd784ada62ddd714d15ee2400c28e1cf |
affected | ||
6.9 |
affected | ||
< 6.9 |
unaffected | ||
6.9.8≤ 6.9.* |
unaffected | ||
6.10≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-41081 | 9.8 CRITICAL | ila: block BH in ila_output() |
| CVE-2024-41073 | 9.8 CRITICAL | nvme: avoid double free special payload |
| CVE-2024-41040 | 9.8 CRITICAL | net/sched: Fix UAF when resolving a clash |
| CVE-2024-41091 | 8.8 HIGH | tun: add missing verification for short frame |
| CVE-2024-42083 | 8.8 HIGH | ionic: fix kernel panic due to multi-buffer handling |
| CVE-2024-41062 | 8.8 HIGH | bluetooth/l2cap: sync sock recv cb and release |
| CVE-2024-41046 | 8.8 HIGH | net: ethernet: lantiq_etop: fix double free in detach |
| CVE-2024-41090 | 8.8 HIGH | tap: add missing verification for short frame |
| CVE-2024-42069 | 7.8 HIGH | net: mana: Fix possible double free in error handling path |
| CVE-2024-41041 | 7.8 HIGH | udp: Set SOCK_RCU_FREE earlier in udp_lib_get_port(). |
| CVE-2024-42064 | 7.8 HIGH | drm/amd/display: Skip pipe if the pipe idx not set properly |
| CVE-2024-41045 | 7.8 HIGH | bpf: Defer work in bpf_timer_cancel_and_free |
| CVE-2024-41017 | 7.8 HIGH | jfs: don't walk off the end of ealist |
| CVE-2024-42066 | 7.8 HIGH | drm/xe: Fix potential integer overflow in page size calculation |
| CVE-2024-41049 | 7.8 HIGH | filelock: fix potential use-after-free in posix_lock_inode |
| CVE-2024-41051 | 7.8 HIGH | cachefiles: wait for ondemand_object_worker to finish when dropping object |
| CVE-2024-42067 | 7.8 HIGH | bpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro() |
| CVE-2024-42068 | 7.8 HIGH | bpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro() |
| CVE-2024-42072 | 7.8 HIGH | bpf: Fix may_goto with negative offset. |
| CVE-2024-41064 | 7.8 HIGH | powerpc/eeh: avoid possible crash when edev->pdev changes |
Showing top 20 of 121 CVEs. View all on vendor page → →
No comments yet