目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-46676— Linux kernel 安全漏洞

AI 预测 7.8 利用难度: 较易 EPSS 0.24% · P16

影响版本矩阵 16

厂商产品版本范围状态
LinuxLinuxdfccd0f580445d176acea174175b3e6518cc91f7< c5e05237444f32f6cfe5d907603a232c77a08b31affected
dfccd0f580445d176acea174175b3e6518cc91f7< 8ddaea033de051ed61b39f6b69ad54a411172b33affected
dfccd0f580445d176acea174175b3e6518cc91f7< 7535db0624a2dede374c42040808ad9a9101d723affected
dfccd0f580445d176acea174175b3e6518cc91f7< 7ecd3dd4f8eecd3309432156ccfe24768e009ec4affected
dfccd0f580445d176acea174175b3e6518cc91f7< 56ad559cf6d87f250a8d203b555dfc3716afa946affected
dfccd0f580445d176acea174175b3e6518cc91f7< 64513d0e546a1f19e390f7e5eba3872bfcbdacf5affected
dfccd0f580445d176acea174175b3e6518cc91f7< febccb39255f9df35527b88c953b2e0deae50e53affected
3.12affected
… +8 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-46676 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
nfc: pn533: Add poll mod list filling check
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: Add poll mod list filling check In case of im_protocols value is 1 and tm_protocols value is 0 this combination successfully passes the check 'if (!im_protocols && !tm_protocols)' in the nfc_start_poll(). But then after pn533_poll_create_mod_list() call in pn533_start_poll() poll mod list will remain empty and dev->poll_mod_count will remain 0 which lead to division by zero. Normally no im protocol has value 1 in the mask, so this combination is not expected by driver. But these protocol values actually come from userspace via Netlink interface (NFC_CMD_START_POLL operation). So a broken or malicious program may pass a message containing a "bad" combination of protocol parameter values so that dev->poll_mod_count is not incremented inside pn533_poll_create_mod_list(), thus leading to division by zero. Call trace looks like: nfc_genl_start_poll() nfc_start_poll() ->start_poll() pn533_start_poll() Add poll mod list filling check. Found by Linux Verification Center (linuxtesting.org) with SVACE.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于在填充轮询模式列表时未检查填充是否成功,可能导致除以零错误。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux dfccd0f580445d176acea174175b3e6518cc91f7 ~ c5e05237444f32f6cfe5d907603a232c77a08b31 -
LinuxLinux 3.12 -

二、漏洞 CVE-2024-46676 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-46676 的情报信息

登录查看更多情报信息。

CVE-2024-46676 补丁与修复 (7)

同批安全公告 · Linux · 2024-09-13 · 共 40 条

CVE-2024-46704Linux kernel 安全漏洞
CVE-2024-46694Linux kernel 安全漏洞
CVE-2024-46696Linux kernel 资源管理错误漏洞
CVE-2024-46695Linux kernel 安全漏洞
CVE-2024-46698Linux kernel 代码问题漏洞
CVE-2024-46697Linux kernel 安全漏洞
CVE-2024-46699Linux kernel 安全漏洞
CVE-2024-46701Linux kernel 安全漏洞
CVE-2024-46702Linux kernel 安全漏洞
CVE-2024-46703Linux kernel 安全漏洞
CVE-2024-46692Linux kernel 安全漏洞
CVE-2024-46705Linux kernel 安全漏洞
CVE-2024-46706Linux kernel 安全漏洞
CVE-2024-46707Linux kernel 安全漏洞
CVE-2024-46709Linux kernel 安全漏洞
CVE-2024-46708Linux kernel 安全漏洞
CVE-2024-46710Linux kernel 安全漏洞
CVE-2024-46711Linux kernel 安全漏洞
CVE-2024-46712Linux kernel 安全漏洞
CVE-2024-46713Linux kernel 安全漏洞

显示前 20 条,共 40 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-46676

暂无评论


发表评论