目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-36909— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 困难 EPSS 0.22% · P13

可能的 ATT&CK 技术 1AI

T1499 · Endpoint Denial of Service

影响版本矩阵 10

厂商产品版本范围状态
LinuxLinuxd4dccf353db80e209f262e3973c834e6e48ba9a9< 2f622008bf784a9f5dd17baa19223cc2ac30a039affected
d4dccf353db80e209f262e3973c834e6e48ba9a9< 82f9e213b124a7d2bb5b16ea35d570260ef467e0affected
d4dccf353db80e209f262e3973c834e6e48ba9a9< a9212a4e2963a7fbe3864ba33dc551d4ad8d0abbaffected
d4dccf353db80e209f262e3973c834e6e48ba9a9< 30d18df6567be09c1433e81993e35e3da573ac48affected
5.16affected
< 5.16unaffected
6.1.91≤ 6.1.*unaffected
6.6.31≤ 6.6.*unaffected
… +2 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-36909 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted In CoCo VMs it is possible for the untrusted host to cause set_memory_encrypted() or set_memory_decrypted() to fail such that an error is returned and the resulting memory is shared. Callers need to take care to handle these errors to avoid returning decrypted (shared) memory to the page allocator, which could lead to functional or security issues. The VMBus ring buffer code could free decrypted/shared pages if set_memory_decrypted() fails. Check the decrypted field in the struct vmbus_gpadl for the ring buffers to decide whether to free the memory.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于 Drivers:hv:vmbus 模块存在漏洞。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux d4dccf353db80e209f262e3973c834e6e48ba9a9 ~ 2f622008bf784a9f5dd17baa19223cc2ac30a039 -
LinuxLinux 5.16 -

二、漏洞 CVE-2024-36909 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-36909 的情报信息

登录查看更多情报信息。

CVE-2024-36909 其他参考 (3)

同批安全公告 · Linux · 2024-05-30 · 共 93 条

CVE-2024-36927Linux kernel 安全漏洞
CVE-2024-36922Linux kernel 安全漏洞
CVE-2024-36920Linux kernel 安全漏洞
CVE-2024-36916Linux kernel 安全漏洞
CVE-2024-36917Linux kernel 安全漏洞
CVE-2024-36914Linux kernel 安全漏洞
CVE-2024-36915Linux kernel 安全漏洞
CVE-2024-36913Linux kernel 安全漏洞
CVE-2024-36919Linux kernel 安全漏洞
CVE-2024-36925Linux kernel 安全漏洞
CVE-2024-36924Linux kernel 安全漏洞
CVE-2024-36926Linux kernel 安全漏洞
CVE-2024-36928Linux kernel 安全漏洞
CVE-2024-36929Linux kernel 安全漏洞
CVE-2024-36930Linux kernel 安全漏洞
CVE-2024-36932Linux kernel 安全漏洞
CVE-2024-36931Linux kernel 安全漏洞
CVE-2024-36933Linux kernel 安全漏洞
CVE-2024-36934Linux kernel 安全漏洞
CVE-2024-36935Linux kernel 安全漏洞

显示前 20 条,共 93 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-36909

暂无评论


发表评论