| Summary | In the Linux kernel, the following vulnerability has been resolved: static_call: Handle module init failure correctly in static_call_del_module() Module insertion invokes static_call_add_module() to initialize the static If that allocation fails the function returns with an error code and the This works correctly, when all keys used by the module were converted over The problem is that key::mods is not a individual struct member of struct union { key::sites is a pointer to the list of built-in usage sites of the static As static_call_del_module() blidly assumes that the pointer is a valid Cure it by checking whether the key has a sites or a mods pointer. If it's a sites pointer then the key is not to be touched. As the sites are If it was converted before the allocation fail, then the inner loop which A fail in the second allocation in __static_call_init() is harmless and |
|---|---|
| Publication Date | Oct. 22, 2024, 3:15 a.m. |
| Registration Date | Oct. 22, 2024, 12:02 p.m. |
| Last Update | Oct. 31, 2024, 6:57 a.m. |
| CVSS3.1 : MEDIUM | |
| スコア | 5.5 |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| 攻撃元区分(AV) | ローカル |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃に必要な特権レベル(PR) | 低 |
| 利用者の関与(UI) | 不要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | なし |
| 可用性への影響(A) | 高 |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 | 6.1.113 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 | 6.10.14 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.11 | 6.11.3 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 | 6.6.55 | |||
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10 | 5.15.168 | |||
| Title | Linux の Linux Kernel における例外的な状態の処理に関する脆弱性 |
|---|---|
| Summary | Linux の Linux Kernel には、例外的な状態の処理に関する脆弱性が存在します。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Sept. 6, 2024, midnight |
| Registration Date | Nov. 1, 2024, 11:58 a.m. |
| Last Update | Nov. 1, 2024, 11:58 a.m. |
| Linux |
| Linux Kernel 5.10 以上 5.15.168 未満 |
| Linux Kernel 5.16 以上 6.1.113 未満 |
| Linux Kernel 6.11 以上 6.11.3 未満 |
| Linux Kernel 6.2 以上 6.6.55 未満 |
| Linux Kernel 6.7 以上 6.10.14 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2024年11月01日] 掲載 | Nov. 1, 2024, 10:43 a.m. |