目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-47809— Linux kernel 安全漏洞

AI Predicted 5.5 Difficulty: Theoretical EPSS 0.22% · P13

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 12

ベンダープロダクトVersion Rangeステータス
LinuxLinux43279e5376017c40b4be9af5bc79cbb4ef6f53d7< e1ffea6bec96d4349dbfcc42ad3e436259f64243affected
43279e5376017c40b4be9af5bc79cbb4ef6f53d7< 8d55ce46dd543c6965970ce70c22c3076dd35b1eaffected
43279e5376017c40b4be9af5bc79cbb4ef6f53d7< 6fbdc3980b70e9c1c86eccea7d5ee68108008fa7affected
43279e5376017c40b4be9af5bc79cbb4ef6f53d7< 2db11504ef82a60c1a2063ba7431a5cd013ecfcbaffected
43279e5376017c40b4be9af5bc79cbb4ef6f53d7< b98333c67daf887c724cd692e88e2db9418c0861affected
2.6.30affected
< 2.6.30unaffected
5.15.209≤ 5.15.*unaffected
… +4 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-47809の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
dlm: fix possible lkb_resource null dereference
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null dereference This patch fixes a possible null pointer dereference when this function is called from request_lock() as lkb->lkb_resource is not assigned yet, only after validate_lock_args() by calling attach_lkb(). Another issue is that a resource name could be a non printable bytearray and we cannot assume to be ASCII coded. The log functionality is probably never being hit when DLM is used in normal way and no debug logging is enabled. The null pointer dereference can only occur on a new created lkb that does not have the resource assigned yet, it probably never hits the null pointer dereference but we should be sure that other changes might not change this behaviour and we actually can hit the mentioned null pointer dereference. In this patch we just drop the printout of the resource name, the lkb id is enough to make a possible connection to a resource name if this exists.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于DLM模块在调用request_lock时,可能导致lkb_resource空指针解引用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 43279e5376017c40b4be9af5bc79cbb4ef6f53d7 ~ e1ffea6bec96d4349dbfcc42ad3e436259f64243 -
LinuxLinux 2.6.30 -

II. CVE-2024-47809の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-47809のインテリジェンス情報

登录查看更多情报信息。

CVE-2024-47809 补丁与修复 (4)

Same Patch Batch · Linux · 2025-01-11 · 67 CVEs total

CVE-2024-474089.8 CRITICALnet/smc: check smcd_v2_ext_offset when receiving proposal msg
CVE-2024-495689.8 CRITICALnet/smc: check v2_ext_offset/eid_cnt/ism_gid_cnt when receiving proposal msg
CVE-2024-578439.8 CRITICALvirtio-net: fix overflow inside virtnet_rq_alloc
CVE-2024-577939.3 CRITICALvirt: tdx-guest: Just leak decrypted memory on unrecoverable errors
CVE-2024-495719.1 CRITICALnet/smc: check iparea_offset and ipv6_prefixes_cnt when receiving proposal msg
CVE-2024-556398.4 HIGHnet: renesas: rswitch: avoid use-after-put for a device tree node
CVE-2024-411497.8 HIGHblock: avoid to reuse `hctx` not removed from cpuhp callback list
CVE-2024-578757.8 HIGHblock: RCU protect disk->conv_zones_bitmap
CVE-2024-477947.8 HIGHbpf: Prevent tailcall infinite loop caused by freplace
CVE-2024-578497.8 HIGHs390/cpum_sf: Handle CPU hotplug remove during sampling
CVE-2024-523197.8 HIGHmm: use aligned address in clear_gigantic_page()
CVE-2024-517297.8 HIGHmm: use aligned address in copy_user_gigantic_page()
CVE-2024-578507.8 HIGHjffs2: Prevent rtime decompress memory corruption
CVE-2024-567887.5 HIGHnet: ethernet: oa_tc6: fix tx skb race condition between reference pointers
CVE-2024-577917.5 HIGHnet/smc: check return value of sock_recvmsg when draining clc data
CVE-2024-495697.5 HIGHnvme-rdma: unquiesce admin_q before destroy it
CVE-2024-578047.3 HIGHscsi: mpi3mr: Fix corrupt config pages PHY state is switched in sysfs
CVE-2024-577927.3 HIGHpower: supply: gpio-charger: Fix set charge current limits
CVE-2024-563687.1 HIGHring-buffer: Fix overflow in __rb_map_vma
CVE-2024-495737.0 HIGHsched/fair: Fix NEXT_BUDDY

Showing 20 of 67 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2024-47809へのコメント

まだコメントはありません


コメントを残す