目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-45025— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 中等 EPSS 0.23% · P14

可能的 ATT&CK 技术 1AI

T1003 · OS Credential Dumping

影响版本矩阵 14

厂商产品版本范围状态
LinuxLinux278a5fbaed89dacd04e9d052f4594ffd0e0585de< fe5bf14881701119aeeda7cf685f3c226c7380dfaffected
278a5fbaed89dacd04e9d052f4594ffd0e0585de< 5053581fe5dfb09b58c65dd8462bf5dea71f41ffaffected
278a5fbaed89dacd04e9d052f4594ffd0e0585de< 8cad3b2b3ab81ca55f37405ffd1315bcc2948058affected
278a5fbaed89dacd04e9d052f4594ffd0e0585de< dd72ae8b0fce9c0bbe9582b9b50820f0407f8d8aaffected
278a5fbaed89dacd04e9d052f4594ffd0e0585de< c69d18f0ac7060de724511537810f10f29a27958affected
278a5fbaed89dacd04e9d052f4594ffd0e0585de< 9a2fa1472083580b6c66bdaf291f591e1170123aaffected
5.9affected
< 5.9unaffected
… +6 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-45025 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps(new, old, count) is expected to copy the first count/BITS_PER_LONG bits from old->full_fds_bits[] and fill the rest with zeroes. What it does is copying enough words (BITS_TO_LONGS(count/BITS_PER_LONG)), then memsets the rest. That works fine, *if* all bits past the cutoff point are clear. Otherwise we are risking garbage from the last word we'd copied. For most of the callers that is true - expand_fdtable() has count equal to old->max_fds, so there's no open descriptors past count, let alone fully occupied words in ->open_fds[], which is what bits in ->full_fds_bits[] correspond to. The other caller (dup_fd()) passes sane_fdtable_size(old_fdt, max_fds), which is the smallest multiple of BITS_PER_LONG that covers all opened descriptors below max_fds. In the common case (copying on fork()) max_fds is ~0U, so all opened descriptors will be below it and we are fine, by the same reasons why the call in expand_fdtable() is safe. Unfortunately, there is a case where max_fds is less than that and where we might, indeed, end up with junk in ->full_fds_bits[] - close_range(from, to, CLOSE_RANGE_UNSHARE) with * descriptor table being currently shared * 'to' being above the current capacity of descriptor table * 'from' being just under some chunk of opened descriptors. In that case we end up with observably wrong behaviour - e.g. spawn a child with CLONE_FILES, get all descriptors in range 0..127 open, then close_range(64, ~0U, CLOSE_RANGE_UNSHARE) and watch dup(0) ending up with descriptor #128, despite #64 being observably not open. The minimally invasive fix would be to deal with that in dup_fd(). If this proves to add measurable overhead, we can go that way, but let's try to fix copy_fd_bitmaps() first. * new helper: bitmap_copy_and_expand(to, from, bits_to_copy, size). * make copy_fd_bitmaps() take the bitmap size in words, rather than bits; it's 'count' argument is always a multiple of BITS_PER_LONG, so we are not losing any information, and that way we can use the same helper for all three bitmaps - compiler will see that count is a multiple of BITS_PER_LONG for the large ones, so it'll generate plain memcpy()+memset(). Reproducer added to tools/testing/selftests/core/close_range_test.c
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于close_range组件存在位图损坏问题。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 278a5fbaed89dacd04e9d052f4594ffd0e0585de ~ fe5bf14881701119aeeda7cf685f3c226c7380df -
LinuxLinux 5.9 -

二、漏洞 CVE-2024-45025 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-45025 的情报信息

登录查看更多情报信息。

CVE-2024-45025 补丁与修复 (8)

同批安全公告 · Linux · 2024-09-11 · 共 23 条

CVE-2024-45019Linux kernel 安全漏洞
CVE-2024-45010Linux kernel 安全漏洞
CVE-2024-45009Linux kernel 安全漏洞
CVE-2024-45011Linux kernel 安全漏洞
CVE-2024-45013Linux kernel 安全漏洞
CVE-2024-45012Linux kernel 安全漏洞
CVE-2024-45015Linux kernel 安全漏洞
CVE-2024-45014Linux kernel 安全漏洞
CVE-2024-45016Linux kernel 安全漏洞
CVE-2024-45018Linux kernel 安全漏洞
CVE-2024-45017Linux kernel 安全漏洞
CVE-2024-46672Linux kernel 安全漏洞
CVE-2024-45021Linux kernel 安全漏洞
CVE-2024-45020Linux kernel 安全漏洞
CVE-2024-45023Linux kernel 安全漏洞
CVE-2024-45022Linux kernel 安全漏洞
CVE-2024-45024Linux kernel 安全漏洞
CVE-2024-45026Linux kernel 安全漏洞
CVE-2024-45027Linux kernel 安全漏洞
CVE-2024-45029Linux kernel 安全漏洞

显示前 20 条,共 23 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-45025

暂无评论


发表评论