目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-26678— Linux kernel 安全漏洞

AI 预测 5.3 利用难度: 极易 EPSS 0.22% · P13

影响版本矩阵 8

厂商产品版本范围状态
LinuxLinuxc4421279b6c278efe129bde7abc64af59ea2dfbd< d327e961573fc335af0ae8a160302205327e1f4eaffected
686b58ce5052842bd34ea94870a2671317331716< 0a962f2fbaa976af9eed21d0306370cded485787affected
3e3eabe26dc88692d34cf76ca0e0dd331481cc15< 4adeeff8c12321cd453412a659c3c0eeb9bb2397affected
3e3eabe26dc88692d34cf76ca0e0dd331481cc15< 1ad55cecf22f05f1c884adf63cc09d3c3e609ebfaffected
6.7affected
< 6.7unaffected
6.7.5≤ 6.7.*unaffected
6.8≤ *unaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-26678 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
x86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: x86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section The .compat section is a dummy PE section that contains the address of the 32-bit entrypoint of the 64-bit kernel image if it is bootable from 32-bit firmware (i.e., CONFIG_EFI_MIXED=y) This section is only 8 bytes in size and is only referenced from the loader, and so it is placed at the end of the memory view of the image, to avoid the need for padding it to 4k, which is required for sections appearing in the middle of the image. Unfortunately, this violates the PE/COFF spec, and even if most EFI loaders will work correctly (including the Tianocore reference implementation), PE loaders do exist that reject such images, on the basis that both the file and memory views of the file contents should be described by the section headers in a monotonically increasing manner without leaving any gaps. So reorganize the sections to avoid this issue. This results in a slight padding overhead (< 4k) which can be avoided if desired by disabling CONFIG_EFI_MIXED (which is only needed in rare cases these days)
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于x86/efistub 中的 compat存在安全问题。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux c4421279b6c278efe129bde7abc64af59ea2dfbd ~ d327e961573fc335af0ae8a160302205327e1f4e -
LinuxLinux 6.7 -

二、漏洞 CVE-2024-26678 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-26678 的情报信息

登录查看更多情报信息。

CVE-2024-26678 其他参考 (4)

同批安全公告 · Linux · 2024-04-02 · 共 35 条

CVE-2024-26676Linux kernel 安全漏洞
CVE-2023-52634Linux kernel 安全漏洞
CVE-2023-52635Linux kernel 安全漏洞
CVE-2024-26671Linux kernel 安全漏洞
CVE-2024-26672Linux kernel 安全漏洞
CVE-2024-26673Linux kernel 安全漏洞
CVE-2023-52636Linux kernel 安全漏洞
CVE-2024-26674Linux kernel 安全漏洞
CVE-2024-26675Linux kernel 安全漏洞
CVE-2023-52633Linux kernel 安全漏洞
CVE-2024-26677Linux kernel 安全漏洞
CVE-2024-26679Linux kernel 安全漏洞
CVE-2024-26680Linux kernel 安全漏洞
CVE-2024-26681Linux kernel 安全漏洞
CVE-2024-26682Linux kernel 安全漏洞
CVE-2024-26683Linux kernel 安全漏洞
CVE-2024-26684Linux kernel 安全漏洞
CVE-2024-26664Linux kernel 安全漏洞
CVE-2024-26657Linux kernel 安全漏洞
CVE-2023-52631Linux kernel 安全漏洞

显示前 20 条,共 35 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26678

暂无评论


发表评论