Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2024-36964— fs/9p: only translate RWX permissions for plain 9P2000

EPSS 0.02% · P6

Affected Version Matrix 19

VendorProductVersion RangeStatus
LinuxLinux45089142b1497dab2327d60f6c71c40766fc3ea4< e90bc596a74bb905e0a45bf346038c3f9d1e868daffected
45089142b1497dab2327d60f6c71c40766fc3ea4< df1962a199783ecd66734d563caf0fedecf08f96affected
45089142b1497dab2327d60f6c71c40766fc3ea4< 5a605930e19f451294bd838754f7d66c976a8a2caffected
45089142b1497dab2327d60f6c71c40766fc3ea4< ad4f65328661392de74e3608bb736fedf3b67e32affected
45089142b1497dab2327d60f6c71c40766fc3ea4< ca9b5c81f0c918c63d73d962ed8a8e231f840bc8affected
45089142b1497dab2327d60f6c71c40766fc3ea4< e55c601af3b1223a84f9f27f9cdbd2af5e203bf3affected
45089142b1497dab2327d60f6c71c40766fc3ea4< 157d468e34fdd3cb1ddc07c2be32fb3b02826b02affected
45089142b1497dab2327d60f6c71c40766fc3ea4< cd25e15e57e68a6b18dc9323047fe9c68b99290baffected
… +11 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-36964

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
fs/9p: only translate RWX permissions for plain 9P2000
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2000 Garbage in plain 9P2000's perm bits is allowed through, which causes it to be able to set (among others) the suid bit. This was presumably not the intent since the unix extended bits are handled explicitly and conditionally on .u.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于 fs/9p 中存在安全问题。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 45089142b1497dab2327d60f6c71c40766fc3ea4 ~ e90bc596a74bb905e0a45bf346038c3f9d1e868d -
LinuxLinux 3.1 -

II. Public POCs for CVE-2024-36964

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-36964

登录查看更多情报信息。

Same Patch Batch · Linux · 2024-06-03 · 5 CVEs total

CVE-2024-36960drm/vmwgfx: Fix invalid reads in fence signaled events
CVE-2024-36962net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs
CVE-2024-36961thermal/debugfs: Fix two locking issues with thermal zone debug
CVE-2024-36963tracefs: Reset permissions on remount if permissions are options

IV. Related Vulnerabilities

V. Comments for CVE-2024-36964

No comments yet


Leave a comment