目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-26685— Linux kernel 安全漏洞

AI 预测 4.3 利用难度: 中等 EPSS 0.25% · P16

可能的 ATT&CK 技术 1AI

T1562.008

影响版本矩阵 26

厂商产品版本范围状态
LinuxLinux7f42ec3941560f0902fe3671e36f2c20ffd3af0a< c4a09fdac625e64abe478dcf88bfa20406616928affected
7f42ec3941560f0902fe3671e36f2c20ffd3af0a< d31c8721e816eff5ca6573cc487754f357c093cdaffected
7f42ec3941560f0902fe3671e36f2c20ffd3af0a< f3e4963566f58726d3265a727116a42b591f6596affected
7f42ec3941560f0902fe3671e36f2c20ffd3af0a< 8fa90634ec3e9cc50f42dd605eec60f2d146ced8affected
7f42ec3941560f0902fe3671e36f2c20ffd3af0a< 6589f0f72f8edd1fa11adce4eedbd3615f2e78abaffected
7f42ec3941560f0902fe3671e36f2c20ffd3af0a< 2c3bdba00283a6c7a5b19481a59a730f46063803affected
7f42ec3941560f0902fe3671e36f2c20ffd3af0a< 626daab3811b772086aef1bf8eed3ffe6f523effaffected
7f42ec3941560f0902fe3671e36f2c20ffd3af0a< 5bc09b397cbf1221f8a8aacb1152650c9195b02baffected
… +18 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-26685 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
nilfs2: fix potential bug in end_buffer_async_write
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential bug in end_buffer_async_write According to a syzbot report, end_buffer_async_write(), which handles the completion of block device writes, may detect abnormal condition of the buffer async_write flag and cause a BUG_ON failure when using nilfs2. Nilfs2 itself does not use end_buffer_async_write(). But, the async_write flag is now used as a marker by commit 7f42ec394156 ("nilfs2: fix issue with race condition of competition between segments for dirty blocks") as a means of resolving double list insertion of dirty blocks in nilfs_lookup_dirty_data_buffers() and nilfs_lookup_node_buffers() and the resulting crash. This modification is safe as long as it is used for file data and b-tree node blocks where the page caches are independent. However, it was irrelevant and redundant to also introduce async_write for segment summary and super root blocks that share buffers with the backing device. This led to the possibility that the BUG_ON check in end_buffer_async_write would fail as described above, if independent writebacks of the backing device occurred in parallel. The use of async_write for segment summary buffers has already been removed in a previous change. Fix this issue by removing the manipulation of the async_write flag for the remaining super root block buffer.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于缓冲区存在错误。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 7f42ec3941560f0902fe3671e36f2c20ffd3af0a ~ c4a09fdac625e64abe478dcf88bfa20406616928 -
LinuxLinux 3.12 -

二、漏洞 CVE-2024-26685 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-26685 的情报信息

登录查看更多情报信息。

CVE-2024-26685 邮件列表归档 (2)

CVE-2024-26685 其他参考 (8)

同批安全公告 · Linux · 2024-04-03 · 共 94 条

CVE-2024-26744Linux kernel 安全漏洞
CVE-2024-26741Linux kernel 安全漏洞
CVE-2024-26739Linux kernel 安全漏洞
CVE-2024-26735Linux kernel 安全漏洞
CVE-2024-26734Linux kernel 安全漏洞
CVE-2024-26733Linux kernel 安全漏洞
CVE-2024-26732Linux kernel 安全漏洞
CVE-2024-26731Linux kernel 安全漏洞
CVE-2024-26736Linux kernel 安全漏洞
CVE-2024-26743Linux kernel 安全漏洞
CVE-2024-26742Linux kernel 安全漏洞
CVE-2024-26747Linux kernel 安全漏洞
CVE-2024-26748Linux kernel 安全漏洞
CVE-2024-26749Linux kernel 安全漏洞
CVE-2024-26751Linux kernel 安全漏洞
CVE-2024-26752Linux kernel 安全漏洞
CVE-2024-26753Linux kernel 安全漏洞
CVE-2024-26754Linux kernel 安全漏洞
CVE-2024-26755Linux kernel 安全漏洞
CVE-2024-26756Linux kernel 安全漏洞

显示前 20 条,共 94 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-26685

暂无评论


发表评论