目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-49975— Linux kernel 安全漏洞

AI Predicted 5.5 Difficulty: Moderate EPSS 0.25% · P16

Possible ATT&CK Techniques 1AI

T1014 · Rootkit

Affected Version Matrix 20

ベンダープロダクトVersion Rangeステータス
LinuxLinuxd4b3b6384f98f8692ad0209891ccdbc7e78bbefe< f31f92107e5a8ecc8902705122c594e979a351feaffected
d4b3b6384f98f8692ad0209891ccdbc7e78bbefe< fe5e9182d3e227476642ae2b312e2356c4d326a3affected
d4b3b6384f98f8692ad0209891ccdbc7e78bbefe< f561b48d633ac2e7d0d667020fc634a96ade33a0affected
d4b3b6384f98f8692ad0209891ccdbc7e78bbefe< 21cb47db1ec9765f91304763a24565ddc22d2492affected
d4b3b6384f98f8692ad0209891ccdbc7e78bbefe< 24141df5a8615790950deedd926a44ddf1dfd6d8affected
d4b3b6384f98f8692ad0209891ccdbc7e78bbefe< 5b981d8335e18aef7908a068529a3287258ff6d8affected
d4b3b6384f98f8692ad0209891ccdbc7e78bbefe< 2aa45f43709ba2082917bd2973d02687075b6eeeaffected
d4b3b6384f98f8692ad0209891ccdbc7e78bbefe< 9634e8dc964a4adafa7e1535147abd7ec29441a6affected
… +12 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-49975の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
uprobes: fix kernel info leak via "[uprobes]" vma
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: uprobes: fix kernel info leak via "[uprobes]" vma xol_add_vma() maps the uninitialized page allocated by __create_xol_area() into userspace. On some architectures (x86) this memory is readable even without VM_READ, VM_EXEC results in the same pgprot_t as VM_EXEC|VM_READ, although this doesn't really matter, debugger can read this memory anyway.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于uprobes组件包含一个内核信息泄露问题。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux d4b3b6384f98f8692ad0209891ccdbc7e78bbefe ~ f31f92107e5a8ecc8902705122c594e979a351fe -
LinuxLinux 3.5 -

II. CVE-2024-49975の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-49975のインテリジェンス情報

登录查看更多情报信息。

CVE-2024-49975 补丁与修复 (9)

Same Patch Batch · Linux · 2024-10-21 · 372 CVEs total

CVE-2024-50019kthread: unpark only parked kthread
CVE-2024-50030drm/xe/ct: prevent UAF in send_recv()
CVE-2024-50028thermal: core: Reference count the zone in thermal_zone_get_by_id()
CVE-2024-50029Bluetooth: hci_conn: Fix UAF in hci_enhanced_setup_sync
CVE-2024-50027thermal: core: Free tzp copy along with the thermal zone
CVE-2024-50025scsi: fnic: Move flush_work initialization out of if block
CVE-2024-50026scsi: wd33c93: Don't use stale scsi_pointer value
CVE-2024-50023net: phy: Remove LED entry from LEDs list on unregister
CVE-2024-50024net: Fix an unsafe loop on the list
CVE-2024-50022device-dax: correct pgoff align in dax_set_mapping()
CVE-2024-50021ice: Fix improper handling of refcount in ice_dpll_init_rclk_pins()
CVE-2024-50020ice: Fix improper handling of refcount in ice_sriov_set_msix_vec_count()
CVE-2024-50011ASoC: Intel: soc-acpi-intel-rpl-match: add missing empty item
CVE-2024-50006ext4: fix i_data_sem unlock order in ext4_ind_migrate()
CVE-2024-50007ALSA: asihpi: Fix potential OOB array access
CVE-2024-50008wifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_cmd_802_11_scan_ext()
CVE-2024-50009cpufreq: amd-pstate: add check for cpufreq_cpu_get's return value
CVE-2024-50010exec: don't WARN for racy path_noexec check
CVE-2024-50014ext4: fix access to uninitialised lock in fc replay path
CVE-2024-50017x86/mm/ident_map: Use gbpages only where full GB page should be mapped.

Showing 20 of 372 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2024-49975へのコメント

まだコメントはありません


コメントを残す