目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2023-52801— Linux kernel 安全漏洞

CVSS 8.8 · High EPSS 0.59% · P45

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 8

ベンダープロダクトVersion Rangeステータス
LinuxLinux51fe6141f0f64ae0bbc096a41a07572273e8c0ef< 836db2e7e4565d8218923b3552304a1637e2f28daffected
51fe6141f0f64ae0bbc096a41a07572273e8c0ef< fcb32111f01ddf3cbd04644cde1773428e31de6aaffected
51fe6141f0f64ae0bbc096a41a07572273e8c0ef< e7250ab7ca4998fe026f2149805b03e09dc32498affected
6.2affected
< 6.2unaffected
6.5.13≤ 6.5.*unaffected
6.6.3≤ 6.6.*unaffected
6.7≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2023-52801の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
iommufd: Fix missing update of domains_itree after splitting iopt_area
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_area_split(), if the original iopt_area has filled a domain and is linked to domains_itree, pages_nodes have to be properly reinserted. Otherwise the domains_itree becomes corrupted and we will UAF.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于iommufd模块存在漏洞。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 51fe6141f0f64ae0bbc096a41a07572273e8c0ef ~ 836db2e7e4565d8218923b3552304a1637e2f28d -
LinuxLinux 6.2 -

II. CVE-2023-52801の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2023-52801のインテリジェンス情報

登录查看更多情报信息。

CVE-2023-52801 其他参考 (3)

Same Patch Batch · Linux · 2024-05-21 · 361 CVEs total

CVE-2021-474279.8 CRITICALscsi: iscsi: Fix iscsi_task use after free
CVE-2021-473289.8 CRITICALscsi: iscsi: Fix conn use after free during resets
CVE-2023-527329.8 CRITICALceph: blocklist the kclient when receiving corrupted snap trace
CVE-2023-527559.8 CRITICALksmbd: fix slab out of bounds write in smb_inherit_dacl()
CVE-2023-527419.8 CRITICALcifs: Fix use-after-free in rdata->read_into_pages()
CVE-2021-472329.8 CRITICALcan: j1939: fix Use-after-Free, hold skb ref while in use
CVE-2021-473789.8 CRITICALnvme-rdma: destroy cm id before destroy qp to avoid use after free
CVE-2023-527698.8 HIGHwifi: ath12k: fix htt mlo-offset event locking
CVE-2021-473088.8 HIGHscsi: libfc: Fix array index out of bound exception
CVE-2023-527988.8 HIGHwifi: ath11k: fix dfs radar event locking
CVE-2023-528468.8 HIGHhsr: Prevent use after free in prp_create_tagged_frame()
CVE-2023-527908.8 HIGHswiotlb: fix out-of-bounds TLB allocations with CONFIG_SWIOTLB_DYNAMIC
CVE-2023-527768.8 HIGHwifi: ath12k: fix dfs-radar and temperature event locking
CVE-2021-473888.8 HIGHmac80211: fix use-after-free in CCMP/GCMP RX
CVE-2021-473908.8 HIGHKVM: x86: Fix stack-out-of-bounds memory access from ioapic_write_indirect()
CVE-2023-528298.4 HIGHwifi: ath12k: fix possible out-of-bound write in ath12k_wmi_ext_hal_reg_caps()
CVE-2021-473528.4 HIGHvirtio-net: Add validation for used length
CVE-2021-472408.4 HIGHnet: qrtr: fix OOB Read in qrtr_endpoint_post
CVE-2021-472458.2 HIGHnetfilter: synproxy: Fix out of bounds when parsing TCP options
CVE-2023-527758.2 HIGHnet/smc: avoid data corruption caused by decline

Showing 20 of 361 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2023-52801へのコメント

まだコメントはありません


コメントを残す