[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256610

 
 

909

 
 

199263

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2024-26946Date: (C)2024-06-19   (M)2024-06-20


In the Linux kernel, the following vulnerability has been resolved: kprobes/x86: Use copy_from_kernel_nofault() to read from unsafe address Read from an unsafe address with copy_from_kernel_nofault() in arch_adjust_kprobe_addr() because this function is used before checking the address is in text or not. Syzcaller bot found a bug and reported the case if user specifies inaccessible data area, arch_adjust_kprobe_addr() will cause a kernel panic. [ mingo: Clarified the comment. ]

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.5CVSS Score :
Exploit Score: Exploit Score:
Impact Score: Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector:
Attack Complexity: Access Complexity:
Privileges Required: Authentication:
User Interaction: Confidentiality:
Scope: Integrity:
Confidentiality: Availability:
Integrity:  
Availability:  
  
Reference:
https://git.kernel.org/stable/c/20fdb21eabaeb8f78f8f701f56d14ea0836ec861
https://git.kernel.org/stable/c/4e51653d5d871f40f1bd5cf95cc7f2d8b33d063b
https://git.kernel.org/stable/c/6417684315087904fffe8966d27ca74398c57dd6
https://git.kernel.org/stable/c/b69f577308f1070004cafac106dd1a44099e5483
https://git.kernel.org/stable/c/f13edd1871d4fb4ab829aff629d47914e251bae3

OVAL    3
oval:org.secpod.oval:def:709006
oval:org.secpod.oval:def:708990
oval:org.secpod.oval:def:708989
XCCDF    1

© SecPod Technologies