目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2024-49974— Linux kernel 安全漏洞

AI 预测 5.3 利用难度: 较易 EPSS 0.27% · P20

可能的 ATT&CK 技术 1AI

T1499 · Endpoint Denial of Service

影响版本矩阵 16

厂商产品版本范围状态
LinuxLinuxe0639dc5805a9d4faaa2c07ad98fa853b9529dd3< 9e52ff544e0bfa09ee339fd7b0937ee3c080c24eaffected
e0639dc5805a9d4faaa2c07ad98fa853b9529dd3< 43e46ee5efc03990b223f7aa8b77aa9c3d3acfdfaffected
e0639dc5805a9d4faaa2c07ad98fa853b9529dd3< 7ea9260874b779637aff6d24c344b8ef4ac862a0affected
e0639dc5805a9d4faaa2c07ad98fa853b9529dd3< ae267989b7b7933dfedcd26468d0a88fc3a9da9eaffected
e0639dc5805a9d4faaa2c07ad98fa853b9529dd3< b4e21431a0db4854b5023cd5af001be557e6c3dbaffected
e0639dc5805a9d4faaa2c07ad98fa853b9529dd3< 6a488ad7745b8f64625c6d3a24ce7e448e83f11baffected
e0639dc5805a9d4faaa2c07ad98fa853b9529dd3< aadc3bbea163b6caaaebfdd2b6c4667fbc726752affected
4.20affected
… +8 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2024-49974 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
NFSD: Limit the number of concurrent async COPY operations
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: NFSD: Limit the number of concurrent async COPY operations Nothing appears to limit the number of concurrent async COPY operations that clients can start. In addition, AFAICT each async COPY can copy an unlimited number of 4MB chunks, so can run for a long time. Thus IMO async COPY can become a DoS vector. Add a restriction mechanism that bounds the number of concurrent background COPY operations. Start simple and try to be fair -- this patch implements a per-namespace limit. An async COPY request that occurs while this limit is exceeded gets NFS4ERR_DELAY. The requesting client can choose to send the request again after a delay or fall back to a traditional read/write style copy. If there is need to make the mechanism more sophisticated, we can visit that in future patches.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于NFSD子系统中对并发异步COPY操作数量的限制不当,可能成为拒绝服务攻击的向量。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux e0639dc5805a9d4faaa2c07ad98fa853b9529dd3 ~ 9e52ff544e0bfa09ee339fd7b0937ee3c080c24e -
LinuxLinux 4.20 -

二、漏洞 CVE-2024-49974 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-49974 的情报信息

登录查看更多情报信息。

CVE-2024-49974 补丁与修复 (5)

同批安全公告 · Linux · 2024-10-21 · 共 372 条

CVE-2024-50019Linux kernel 安全漏洞
CVE-2024-50030Linux kernel 安全漏洞
CVE-2024-50028Linux kernel 安全漏洞
CVE-2024-50029Linux kernel 安全漏洞
CVE-2024-50027Linux kernel 安全漏洞
CVE-2024-50025Linux kernel 安全漏洞
CVE-2024-50026Linux kernel 安全漏洞
CVE-2024-50023Linux kernel 安全漏洞
CVE-2024-50024Linux kernel 安全漏洞
CVE-2024-50022Linux kernel 安全漏洞
CVE-2024-50021Linux kernel 安全漏洞
CVE-2024-50020Linux kernel 安全漏洞
CVE-2024-50011Linux kernel 安全漏洞
CVE-2024-50006Linux kernel 安全漏洞
CVE-2024-50007Linux kernel 安全漏洞
CVE-2024-50008Linux kernel 安全漏洞
CVE-2024-50009Linux kernel 安全漏洞
CVE-2024-50010Linux kernel 安全漏洞
CVE-2024-50014Linux kernel 安全漏洞
CVE-2024-50017Linux kernel 安全漏洞

显示前 20 条,共 372 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-49974

暂无评论


发表评论