目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2024-57933— Linux kernel 安全漏洞

AI Predicted 5.5 Difficulty: Moderate EPSS 0.20% · P11

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 8

ベンダープロダクトVersion Rangeステータス
LinuxLinuxfd8e40321a12391e6f554cc637d0c4b6109682a9< 771d66f2bd8c4dba1286a9163ab982cecd825718affected
fd8e40321a12391e6f554cc637d0c4b6109682a9< 8e8d7037c89437af12725f454e2eaf40e8166c0faffected
fd8e40321a12391e6f554cc637d0c4b6109682a9< 40338d7987d810fcaa95c500b1068a52b08eec9baffected
6.4affected
< 6.4unaffected
6.6.70≤ 6.6.*unaffected
6.12.9≤ 6.12.*unaffected
6.13≤ *unaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2024-57933の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
gve: guard XSK operations on the existence of queues
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: gve: guard XSK operations on the existence of queues This patch predicates the enabling and disabling of XSK pools on the existence of queues. As it stands, if the interface is down, disabling or enabling XSK pools would result in a crash, as the RX queue pointer would be NULL. XSK pool registration will occur as part of the next interface up. Similarly, xsk_wakeup needs be guarded against queues disappearing while the function is executing, so a check against the GVE_PRIV_FLAGS_NAPI_ENABLED flag is added to synchronize with the disabling of the bit and the synchronize_net() in gve_turndown.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于gve模块在XSK操作中未检查队列是否存在。这可能导致系统崩溃或XSK操作失败。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux fd8e40321a12391e6f554cc637d0c4b6109682a9 ~ 771d66f2bd8c4dba1286a9163ab982cecd825718 -
LinuxLinux 6.4 -

II. CVE-2024-57933の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2024-57933のインテリジェンス情報

登录查看更多情报信息。

CVE-2024-57933 补丁与修复 (3)

Same Patch Batch · Linux · 2025-01-21 · 25 CVEs total

CVE-2024-57944iio: adc: ti-ads1298: Add NULL check in ads1298_init
CVE-2024-57946virtio-blk: don't keep queue frozen during system suspend
CVE-2025-21664dm thin: make get_first_thin use rcu-safe list first function
CVE-2025-21663net: stmmac: dwmac-tegra: Read iommu stream id from device tree
CVE-2025-21662net/mlx5: Fix variable not being completed when function returns
CVE-2025-21661gpio: virtuser: fix missing lookup table cleanups
CVE-2025-21660ksmbd: fix unexpectedly changed path in ksmbd_vfs_kern_path_locked
CVE-2025-21659netdev: prevent accessing NAPI instances from another namespace
CVE-2025-21658btrfs: avoid NULL pointer dereference if no valid extent tree
CVE-2025-21657sched_ext: Replace rq_lock() to raw_spin_rq_lock() in scx_ops_bypass()
CVE-2024-57945riscv: mm: Fix the out of bound issue of vmemmap address
CVE-2025-21656hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur
CVE-2024-57930tracing: Have process_string() also allow arrays
CVE-2024-57943exfat: fix the new buffer was not zeroed before writing
CVE-2024-57942netfs: Fix ceph copy to cache on write-begin
CVE-2024-57941netfs: Fix the (non-)cancellation of copy when cache is temporarily disabled
CVE-2024-57940exfat: fix the infinite loop in exfat_readdir()
CVE-2024-57939riscv: Fix sleeping in invalid context in die()
CVE-2024-57938net/sctp: Prevent autoclose integer overflow in sctp_association_init()
CVE-2024-57936RDMA/bnxt_re: Fix max SGEs for the Work Request

Showing 20 of 25 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2024-57933へのコメント

まだコメントはありません


コメントを残す