目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-42136— Linux kernel 安全漏洞

AI Predicted 5.5 Difficulty: Theoretical EPSS 0.24% · P15

Possible ATT&CK Techniques 1AI

T1200 · Hardware Additions

Affected Version Matrix 10

ベンダープロダクトVersion Rangeステータス
LinuxLinux67f1e027c27054e641584655020a417eaac9cb3a< 0c97527e916054acc4a46ffb02842988acb2e92baffected
67f1e027c27054e641584655020a417eaac9cb3a< 3ee21e14c8c329168a0b66bab00ecd18f5d0dee3affected
67f1e027c27054e641584655020a417eaac9cb3a< e809bc112712da8f7e15822674c6562da6cdf24caffected
67f1e027c27054e641584655020a417eaac9cb3a< efb905aeb44b0e99c0e6b07865b1885ae0471ebfaffected
5.16affected
< 5.16unaffected
6.1.98≤ 6.1.*unaffected
6.6.39≤ 6.6.*unaffected
… +2 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-42136の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
cdrom: rearrange last_media_change check to avoid unintentional overflow
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: cdrom: rearrange last_media_change check to avoid unintentional overflow When running syzkaller with the newly reintroduced signed integer wrap sanitizer we encounter this splat: [ 366.015950] UBSAN: signed-integer-overflow in ../drivers/cdrom/cdrom.c:2361:33 [ 366.021089] -9223372036854775808 - 346321 cannot be represented in type '__s64' (aka 'long long') [ 366.025894] program syz-executor.4 is using a deprecated SCSI ioctl, please convert it to SG_IO [ 366.027502] CPU: 5 PID: 28472 Comm: syz-executor.7 Not tainted 6.8.0-rc2-00035-gb3ef86b5a957 #1 [ 366.027512] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 366.027518] Call Trace: [ 366.027523] <TASK> [ 366.027533] dump_stack_lvl+0x93/0xd0 [ 366.027899] handle_overflow+0x171/0x1b0 [ 366.038787] ata1.00: invalid multi_count 32 ignored [ 366.043924] cdrom_ioctl+0x2c3f/0x2d10 [ 366.063932] ? __pm_runtime_resume+0xe6/0x130 [ 366.071923] sr_block_ioctl+0x15d/0x1d0 [ 366.074624] ? __pfx_sr_block_ioctl+0x10/0x10 [ 366.077642] blkdev_ioctl+0x419/0x500 [ 366.080231] ? __pfx_blkdev_ioctl+0x10/0x10 ... Historically, the signed integer overflow sanitizer did not work in the kernel due to its interaction with `-fwrapv` but this has since been changed [1] in the newest version of Clang. It was re-enabled in the kernel with Commit 557f8c582a9ba8ab ("ubsan: Reintroduce signed overflow sanitizer"). Let's rearrange the check to not perform any arithmetic, thus not tripping the sanitizer.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel 存在安全漏洞,该漏洞源于cdrom模块中在检查上次媒体变更时,发生整数溢出。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 67f1e027c27054e641584655020a417eaac9cb3a ~ 0c97527e916054acc4a46ffb02842988acb2e92b -
LinuxLinux 5.16 -

II. CVE-2024-42136の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-42136のインテリジェンス情報

登录查看更多情报信息。

CVE-2024-42136 其他参考 (4)

Same Patch Batch · Linux · 2024-07-30 · 70 CVEs total

CVE-2024-421089.8 CRITICALnet: rswitch: Avoid use-after-free in rswitch_poll()
CVE-2024-422258.3 HIGHwifi: mt76: replace skb_put with skb_put_zero
CVE-2024-421207.8 HIGHdrm/amd/display: Check pipe offset before setting vblank
CVE-2024-421157.8 HIGHjffs2: Fix potential illegal address access in jffs2_free_inode
CVE-2024-421127.8 HIGHnet: txgbe: free isb resources at the right time
CVE-2024-421117.8 HIGHbtrfs: always do the basic checks for btrfs_qgroup_inherit structure
CVE-2024-421177.8 HIGHdrm/amd/display: ASSERT when failing to find index by plane/stream id
CVE-2024-421097.8 HIGHnetfilter: nf_tables: unconditionally flush pending work before notifier
CVE-2024-421627.8 HIGHgve: Account for stopped queues when reading NIC stats
CVE-2024-421057.8 HIGHnilfs2: fix inode number range checks
CVE-2024-421047.8 HIGHnilfs2: add missing check for inode numbers on directory entries
CVE-2024-421037.8 HIGHbtrfs: fix adding block group to a reclaim list and the unused list during reclaim
CVE-2024-420997.8 HIGHs390/dasd: Fix invalid dereferencing of indirect CCW data pointer
CVE-2024-421327.6 HIGHbluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX
CVE-2024-421337.6 HIGHBluetooth: Ignore too large handle values in BIG
CVE-2024-421527.5 HIGHnvmet: fix a possible leak when destroy a ctrl during qp establishment
CVE-2024-421107.5 HIGHnet: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx()
CVE-2024-421457.5 HIGHIB/core: Implement a limit on UMAD receive List
CVE-2024-421237.0 HIGHdrm/amdgpu: fix double free err_addr pointer warnings
CVE-2024-422247.0 HIGHnet: dsa: mv88e6xxx: Correct check for empty list

Showing 20 of 70 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2024-42136へのコメント

まだコメントはありません


コメントを残す