目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-44941— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 中等 EPSS 0.21% · P12

影响版本矩阵 8

厂商产品版本范围状态
LinuxLinux98e4da8ca301e062d79ae168c67e56f3c3de3ce4< 263df78166d3a9609b97d28c34029bd01874cbb8affected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4< 323ef20b5558b9d9fd10c1224327af6f11a8177daffected
98e4da8ca301e062d79ae168c67e56f3c3de3ce4< d7409b05a64f212735f0d33f5f1602051a886eabaffected
3.8affected
< 3.8unaffected
6.6.47≤ 6.6.*unaffected
6.10.6≤ 6.10.*unaffected
6.11≤ *unaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-44941 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
f2fs: fix to cover read extent cache access with lock
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to cover read extent cache access with lock syzbot reports a f2fs bug as below: BUG: KASAN: slab-use-after-free in sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46 Read of size 4 at addr ffff8880739ab220 by task syz-executor200/5097 CPU: 0 PID: 5097 Comm: syz-executor200 Not tainted 6.9.0-rc6-syzkaller #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114 print_address_description mm/kasan/report.c:377 [inline] print_report+0x169/0x550 mm/kasan/report.c:488 kasan_report+0x143/0x180 mm/kasan/report.c:601 sanity_check_extent_cache+0x370/0x410 fs/f2fs/extent_cache.c:46 do_read_inode fs/f2fs/inode.c:509 [inline] f2fs_iget+0x33e1/0x46e0 fs/f2fs/inode.c:560 f2fs_nfs_get_inode+0x74/0x100 fs/f2fs/super.c:3237 generic_fh_to_dentry+0x9f/0xf0 fs/libfs.c:1413 exportfs_decode_fh_raw+0x152/0x5f0 fs/exportfs/expfs.c:444 exportfs_decode_fh+0x3c/0x80 fs/exportfs/expfs.c:584 do_handle_to_path fs/fhandle.c:155 [inline] handle_to_path fs/fhandle.c:210 [inline] do_handle_open+0x495/0x650 fs/fhandle.c:226 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f We missed to cover sanity_check_extent_cache() w/ extent cache lock, so, below race case may happen, result in use after free issue. - f2fs_iget - do_read_inode - f2fs_init_read_extent_tree : add largest extent entry in to cache - shrink - f2fs_shrink_read_extent_tree - __shrink_extent_tree - __detach_extent_node : drop largest extent entry - sanity_check_extent_cache : access et->largest w/o lock let's refactor sanity_check_extent_cache() to avoid extent cache access and call it before f2fs_init_read_extent_tree() to fix this issue.
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在sanity_check_extent_cache函数中未正确锁定,导致内存释放后重用问题。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 98e4da8ca301e062d79ae168c67e56f3c3de3ce4 ~ 263df78166d3a9609b97d28c34029bd01874cbb8 -
LinuxLinux 3.8 -

二、漏洞 CVE-2024-44941 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-44941 的情报信息

登录查看更多情报信息。

CVE-2024-44941 其他参考 (3)

同批安全公告 · Linux · 2024-08-26 · 共 39 条

CVE-2024-44933Linux kernel 安全漏洞
CVE-2024-43908Linux kernel 安全漏洞
CVE-2024-43909Linux kernel 安全漏洞
CVE-2024-43910Linux kernel 安全漏洞
CVE-2024-43911Linux kernel 安全漏洞
CVE-2024-43912Linux kernel 安全漏洞
CVE-2024-43913Linux kernel 安全漏洞
CVE-2024-43914Linux kernel 安全漏洞
CVE-2024-44931Linux kernel 安全漏洞
CVE-2024-44932Linux kernel 安全漏洞
CVE-2024-43907Linux kernel 安全漏洞
CVE-2024-44934Linux kernel 安全漏洞
CVE-2024-44935Linux kernel 安全漏洞
CVE-2024-44936Linux kernel 安全漏洞
CVE-2024-44937Linux kernel 安全漏洞
CVE-2024-44938Linux kernel 安全漏洞
CVE-2024-44939Linux kernel 安全漏洞
CVE-2024-44940Linux kernel 安全漏洞
CVE-2024-44942Linux kernel 安全漏洞
CVE-2024-43896Linux kernel 安全漏洞

显示前 20 条,共 39 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-44941

暂无评论


发表评论