目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-46695— Linux kernel 安全漏洞

CVSS 9.8 · Critical EPSS 0.53% · P42

影响版本矩阵 14

厂商产品版本范围状态
LinuxLinux18032ca062e621e15683cb61c066ef3dc5414a7b< 2dbc4b7bac60b02cc6e70d05bf6a7dfd551f9ddaaffected
18032ca062e621e15683cb61c066ef3dc5414a7b< fe0cd53791119f6287b6532af8ce41576d664930affected
18032ca062e621e15683cb61c066ef3dc5414a7b< eebec98791d0137e455cc006411bb92a54250924affected
18032ca062e621e15683cb61c066ef3dc5414a7b< 459584258d47ec3cc6245a82e8a49c9d08eb8b57affected
18032ca062e621e15683cb61c066ef3dc5414a7b< f71ec019257ba4f7ab198bd948c5902a207bad96affected
18032ca062e621e15683cb61c066ef3dc5414a7b< 76a0e79bc84f466999fa501fce5bf7a07641b8a7affected
3.11affected
< 3.11unaffected
… +6 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-46695 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
selinux,smack: don't bypass permissions check in inode_setsecctx hook
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on files on an NFS filesystem that is exported with root squashing enabled. The end of the kerneldoc comment for __vfs_setxattr_noperm() states: * This function requires the caller to lock the inode's i_mutex before it * is executed. It also assumes that the caller will make the appropriate * permission checks. nfsd_setattr() does do permissions checking via fh_verify() and nfsd_permission(), but those don't do all the same permissions checks that are done by security_inode_setxattr() and its related LSM hooks do. Since nfsd_setattr() is the only consumer of security_inode_setsecctx(), simplest solution appears to be to replace the call to __vfs_setxattr_noperm() with a call to __vfs_setxattr_locked(). This fixes the above issue and has the added benefit of causing nfsd to recall conflicting delegations on a file when a client tries to change its security label.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于允许绕过权限检查。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 18032ca062e621e15683cb61c066ef3dc5414a7b ~ 2dbc4b7bac60b02cc6e70d05bf6a7dfd551f9dda -
LinuxLinux 3.11 -

二、漏洞 CVE-2024-46695 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-46695 的情报信息

登录查看更多情报信息。

CVE-2024-46695 其他参考 (1)

同批安全公告 · Linux · 2024-09-13 · 共 40 条

CVE-2024-466979.8 CRITICALLinux kernel 安全漏洞
CVE-2024-466969.8 CRITICALLinux kernel 资源管理错误漏洞
CVE-2024-466909.8 CRITICALLinux kernel 安全漏洞
CVE-2024-466737.8 HIGHLinux kernel 资源管理错误漏洞
CVE-2024-467137.8 HIGHLinux kernel 安全漏洞
CVE-2024-467107.8 HIGHLinux kernel 安全漏洞
CVE-2024-467097.8 HIGHLinux kernel 安全漏洞
CVE-2024-467057.8 HIGHLinux kernel 安全漏洞
CVE-2024-466877.8 HIGHLinux kernel 安全漏洞
CVE-2024-466837.8 HIGHLinux kernel 资源管理错误漏洞
CVE-2024-466747.8 HIGHLinux kernel 资源管理错误漏洞
CVE-2024-466807.8 HIGHLinux kernel 安全漏洞
CVE-2024-466787.8 HIGHLinux kernel 安全漏洞
CVE-2024-46679Linux kernel 安全漏洞
CVE-2024-46712Linux kernel 安全漏洞
CVE-2024-46711Linux kernel 安全漏洞
CVE-2024-46675Linux kernel 安全漏洞
CVE-2024-46708Linux kernel 安全漏洞
CVE-2024-46676Linux kernel 安全漏洞
CVE-2024-46707Linux kernel 安全漏洞

显示前 20 条,共 40 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-46695

暂无评论


发表评论