目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-53136— Linux kernel 安全漏洞

AI Predicted 5.0 Difficulty: Hard EPSS 0.17% · P6

Possible ATT&CK Techniques 1AI

T1053.007 · Container Orchestration Job

Affected Version Matrix 15

ベンダープロダクトVersion Rangeステータス
LinuxLinux9fb9703cd43ee20a6de8ccdef991677b7274cec0< 36b537e8f302f670c7cf35d88a3a294443e32d52affected
7cc30ada84323be19395094d567579536e0d187e< a3c65022d89d5baa2cea8e87a6de983ea305f14caffected
bda1a99a0dd644f31a87d636ac624eeb975cb65a< 57cc8d253099d1b8627f0fb487ee011d9158ccc9affected
3d9528484480e8f4979b3a347930ed383be99f89< d3f9d88c2c03b2646ace336236adca19f7697bd3affected
82cae1e30bd940253593c2d4f16d88343d1358f4< 5874c1150e77296565ad6e495ef41fbf87570d14affected
edd1f905050686fdc4cfe233d818469fdf7d5ff8< 64e67e8694252c1bf01b802ee911be3fee62c36baffected
ffd56612566bc23877c8f45def2801f3324a222a< 901dc2ad7c3789fa87dc3956f6697c5d62d5cf7eaffected
d949d1d14fa281ace388b1de978e8f2cd52875cf< d1aa0c04294e29883d65eac6c2f72fe95cc7c049affected
… +7 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-53136の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
mm: revert "mm: shmem: fix data-race in shmem_getattr()"
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getattr()" Revert d949d1d14fa2 ("mm: shmem: fix data-race in shmem_getattr()") as suggested by Chuck [1]. It is causing deadlocks when accessing tmpfs over NFS. As Hugh commented, "added just to silence a syzbot sanitizer splat: added where there has never been any practical problem".
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于mm/shmem模块中由于撤销先前的数据竞争修复导致的死锁问题。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 9fb9703cd43ee20a6de8ccdef991677b7274cec0 ~ 36b537e8f302f670c7cf35d88a3a294443e32d52 -
LinuxLinux 4.19.323 ~ 4.19.325 -

II. CVE-2024-53136の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-53136のインテリジェンス情報

登录查看更多情报信息。

CVE-2024-53136 补丁与修复 (8)

Same Patch Batch · Linux · 2024-12-04 · 16 CVEs total

CVE-2024-53125bpf: sync_linked_regs() must preserve subreg_def
CVE-2024-53126vdpa: solidrun: Fix UB bug with devres
CVE-2024-53127Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K"
CVE-2024-53128sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers
CVE-2024-53129drm/rockchip: vop: Fix a dereferenced before check warning
CVE-2024-53130nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint
CVE-2024-53131nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint
CVE-2024-53132drm/xe/oa: Fix "Missing outer runtime PM protection" warning
CVE-2024-53133drm/amd/display: Handle dml allocation failure to avoid crash
CVE-2024-53134pmdomain: imx93-blk-ctrl: correct remove path
CVE-2024-53135KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
CVE-2024-53138net/mlx5e: kTLS, Fix incorrect page refcounting
CVE-2024-53137ARM: fix cacheflush with PAN
CVE-2024-53139sctp: fix possible UAF in sctp_v6_available()
CVE-2024-53140netlink: terminate outstanding dump on socket close

IV. 関連脆弱性

V. CVE-2024-53136へのコメント

まだコメントはありません


コメントを残す