Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-52642— media: rc: bpf attach/detach requires write permission

AI Predicted 5.5 Difficulty: Hard EPSS 0.21% · P11

Affected Version Matrix 14

VendorProductVersion RangeStatus
LinuxLinuxf4364dcfc86df7c1ca47b256eaf6b6d0cdd0d936< 93d8109bf182510629bbefc8cd45296d2393987faffected
f4364dcfc86df7c1ca47b256eaf6b6d0cdd0d936< d98210108e7b2ff64b332b0a3541c8ad6a0617b0affected
f4364dcfc86df7c1ca47b256eaf6b6d0cdd0d936< 9f6087851ec6dce5b15f694aeaf3e8ec8243224eaffected
f4364dcfc86df7c1ca47b256eaf6b6d0cdd0d936< 93136132d1b5792bf44151e3494ae3691cd738e8affected
f4364dcfc86df7c1ca47b256eaf6b6d0cdd0d936< caf2da1d4562de4e35eedec0be2b7f1ee25d83beaffected
f4364dcfc86df7c1ca47b256eaf6b6d0cdd0d936< 6a9d552483d50953320b9d3b57abdee8d436f23faffected
4.18affected
< 4.18unaffected
… +6 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-52642

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
media: rc: bpf attach/detach requires write permission
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: media: rc: bpf attach/detach requires write permission Note that bpf attach/detach also requires CAP_NET_ADMIN.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux f4364dcfc86df7c1ca47b256eaf6b6d0cdd0d936 ~ 93d8109bf182510629bbefc8cd45296d2393987f -
LinuxLinux 4.18 -

II. Public POCs for CVE-2023-52642

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-52642

登录查看更多情报信息。

Mailing List Discussions for CVE-2023-52642 (1)

Other References for CVE-2023-52642 (6)

Same Patch Batch · Linux · 2024-04-17 · 100 CVEs total

CVE-2024-268539.8 CRITICALigc: avoid returning frame twice in XDP_REDIRECT
CVE-2024-268779.8 CRITICALcrypto: xilinx - call finalize with bh disabled
CVE-2024-268289.4 CRITICALcifs: fix underflow in parse_server_interfaces()
CVE-2024-268568.8 HIGHnet: sparx5: Fix use after free inside sparx5_del_mact_entry
CVE-2024-268228.7 HIGHsmb: client: set correct id, uid and cruid for multiuser automounts
CVE-2024-268308.4 HIGHi40e: Do not allow untrusted VF to remove administratively set MAC
CVE-2024-268907.8 HIGHBluetooth: btrtl: fix out of bounds memory access
CVE-2024-268837.8 HIGHbpf: Fix stackmap overflow check on 32-bit arches
CVE-2024-268247.8 HIGHcrypto: algif_hash - Remove bogus SGL free on zero-length error path
CVE-2024-268707.8 HIGHNFSv4.2: fix nfs4_listxattr kernel BUG at mm/usercopy.c:102
CVE-2024-268237.8 HIGHirqchip/gic-v3-its: Restore quirk probing for ACPI-based systems
CVE-2024-268697.8 HIGHf2fs: fix to truncate meta inode pages forcely
CVE-2024-269117.8 HIGHdrm/buddy: Fix alloc_range() error handling code
CVE-2024-268387.8 HIGHRDMA/irdma: Fix KASAN issue with tasklet
CVE-2024-268657.8 HIGHrds: tcp: Fix use-after-free of net in reqsk_timer_handler().
CVE-2024-268647.8 HIGHtcp: Fix refcnt handling in __inet_hash_connect().
CVE-2024-268727.8 HIGHRDMA/srpt: Do not register event handler until srpt device is fully setup
CVE-2024-268957.8 HIGHwifi: wilc1000: prevent use-after-free on vif when cleaning up all interfaces
CVE-2024-268987.8 HIGHaoe: fix the potential use-after-free problem in aoecmd_cfg_pkts
CVE-2024-268527.8 HIGHnet/ipv6: avoid possible UAF in ip6_route_mpath_notify()

Showing top 20 of 100 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2023-52642

No comments yet


Leave a comment