CVE-2024-2394
published 2024-03-12CVE-2024-2394: A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.56%
43.2th percentile
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Admin/add-admin.php. The manipulation of the argument avatar leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256454 is the identifier assigned to this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | employee_management_system | — | — |
| walterjnr1 | employee_management_system | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:L/Au:M/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2023-52620 kernel: netfilter: nf_tables: disallow timeout for anonymous sets
bugzilla·2024-03-21·CVSS 2.5
CVE-2023-52620 [LOW] CVE-2023-52620 kernel: netfilter: nf_tables: disallow timeout for anonymous sets
CVE-2023-52620 kernel: netfilter: nf_tables: disallow timeout for anonymous sets
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: disallow timeout for anonymous sets
The Linux kernel CVE team has assigned CVE-2023-52620 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024032147-CVE-2023-52620-11a9@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Bugzilla
CVE-2024-26633 kernel: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
bugzilla·2024-03-18·CVSS 5.5
CVE-2024-26633 [MEDIUM] CVE-2024-26633 kernel: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
CVE-2024-26633 kernel: ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: fix NEXTHDR_FRAGMENT handling in ip6_tnl_parse_tlv_enc_lim()
The Linux kernel CVE team has assigned CVE-2024-26633 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/[email protected]/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2270119]
---
This was fixed for Fedora with the 6.6.14 stable kernel update.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
Bugzilla
CVE-2023-52529 kernel: HID: sony: Fix a potential memory leak in sony_probe()
bugzilla·2024-03-04·CVSS 6.0
CVE-2023-52529 [MEDIUM] CVE-2023-52529 kernel: HID: sony: Fix a potential memory leak in sony_probe()
CVE-2023-52529 kernel: HID: sony: Fix a potential memory leak in sony_probe()
In the Linux kernel, the following vulnerability has been resolved:
HID: sony: Fix a potential memory leak in sony_probe()
The Linux kernel CVE team has assigned CVE-2023-52529 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030255-CVE-2023-52529-56ff@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2023-52529 is: CHECK Maybe valid. Check manually. with impact LOW (that is an approximation based on flags USB INIT SIMPLEFIX LEAK ; these flags parsed automatically
Bugzilla
CVE-2023-52580 kernel: net/core: kernel crash in ETH_P_1588 flow dissector
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52580 [MEDIUM] CVE-2023-52580 kernel: net/core: kernel crash in ETH_P_1588 flow dissector
CVE-2023-52580 kernel: net/core: kernel crash in ETH_P_1588 flow dissector
In the Linux kernel, the following vulnerability has been resolved:
net/core: Fix ETH_P_1588 flow dissector
The Linux kernel CVE team has assigned CVE-2023-52580 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030258-CVE-2023-52580-c37e@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:3138 ht
Bugzilla
CVE-2023-52581 kernel: netfilter: nf_tables: memory leak when more than 255 elements expired
bugzilla·2024-03-04·CVSS 6.3
CVE-2023-52581 [MEDIUM] CVE-2023-52581 kernel: netfilter: nf_tables: memory leak when more than 255 elements expired
CVE-2023-52581 kernel: netfilter: nf_tables: memory leak when more than 255 elements expired
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix memleak when more than 255 elements expired
The Linux kernel CVE team has assigned CVE-2023-52581 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030258-CVE-2023-52581-2165@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issue has been addressed in the following products:
R
Bugzilla
CVE-2023-52578 kernel: net: bridge: data races indata-races in br_handle_frame_finish()
bugzilla·2024-03-04·CVSS 7.0
CVE-2023-52578 [HIGH] CVE-2023-52578 kernel: net: bridge: data races indata-races in br_handle_frame_finish()
CVE-2023-52578 kernel: net: bridge: data races indata-races in br_handle_frame_finish()
In the Linux kernel, the following vulnerability has been resolved:
net: bridge: use DEV_STATS_INC()
The Linux kernel CVE team has assigned CVE-2023-52578 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030257-CVE-2023-52578-50cb@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8.6 Extended Update Support
Via RHSA-2024:3462 https://access.redhat.com/errata/RHSA-2024:3462
---
This issue has been addressed in the following products:
Red Hat Enterpris
Bugzilla
CVE-2023-52574 kernel: team: NULL pointer dereference when team device type is changed
bugzilla·2024-03-04·CVSS 5.5
CVE-2023-52574 [MEDIUM] CVE-2023-52574 kernel: team: NULL pointer dereference when team device type is changed
CVE-2023-52574 kernel: team: NULL pointer dereference when team device type is changed
In the Linux kernel, the following vulnerability has been resolved:
team: fix null-ptr-deref when team device type is changed
The Linux kernel CVE team has assigned CVE-2023-52574 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030256-CVE-2023-52574-a423@gregkh/T/#u
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issue has been addressed in the following products:
Red Hat Enterprise
Bugzilla
CVE-2023-52476 kernel: perf/x86/lbr: Filter vsyscall addresses
bugzilla·2024-02-29·CVSS 5.5
CVE-2023-52476 [MEDIUM] CVE-2023-52476 kernel: perf/x86/lbr: Filter vsyscall addresses
CVE-2023-52476 kernel: perf/x86/lbr: Filter vsyscall addresses
In the Linux kernel, the following vulnerability has been resolved:
perf/x86/lbr: Filter vsyscall addresses
The Linux kernel CVE team has assigned CVE-2023-52476 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024022921-CVE-2023-52476-e307@gregkh/T/#u
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2267042]
---
This was fixed for Fedora with the 6.5.8 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
Updated trackers in new status to affected/delegated to set SLA expectations appropriately
---
The result of automatic c
Bugzilla
CVE-2024-26593 kernel: i2c: i801: Fix block process call transactions
bugzilla·2024-02-23·CVSS 7.1
CVE-2024-26593 [HIGH] CVE-2024-26593 kernel: i2c: i801: Fix block process call transactions
CVE-2024-26593 kernel: i2c: i801: Fix block process call transactions
i2c: i801: Fix block process call transactions
According to the Intel datasheets, software must reset the block
buffer index twice for block process call transactions: once before
writing the outgoing data to the buffer, and once again before
reading the incoming data from the buffer.
The driver is currently missing the second reset, causing the wrong
portion of the block buffer to be read.
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2265898]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterpri
Bugzilla
CVE-2023-51780 kernel: use-after-free in net/atm/ioctl.c
bugzilla·2024-01-10·CVSS 7.0
CVE-2023-51780 [HIGH] CVE-2023-51780 kernel: use-after-free in net/atm/ioctl.c
CVE-2023-51780 kernel: use-after-free in net/atm/ioctl.c
An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2257684]
---
This was fixed for Fedora with the 6.6.8 stable kernel updates.
---
Where is the patch for this one? Can't see it in here and I can't open the parent bug.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issu
Bugzilla
CVE-2023-24023 kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses
bugzilla·2023-12-18·CVSS 6.8
CVE-2023-24023 [MEDIUM] CVE-2023-24023 kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses
CVE-2023-24023 kernel: Bluetooth Forward and Future Secrecy Attacks and Defenses
Bluetooth BR/EDR devices with Secure Simple Pairing and Secure Connections pairing in Bluetooth Core Specification 4.2 through 5.4 allow certain man-in-the-middle attacks that force a short key length, and might lead to discovery of the encryption key and live injection, aka BLUFFS.
Refer:
https://www.bluetooth.com/learn-about-bluetooth/key-attributes/bluetooth-security/bluffs-vulnerability/
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2254962]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red H
Bugzilla
CVE-2023-6622 kernel: null pointer dereference vulnerability in nft_dynset_init()
bugzilla·2023-12-08·CVSS 5.5
CVE-2023-6622 [MEDIUM] CVE-2023-6622 kernel: null pointer dereference vulnerability in nft_dynset_init()
CVE-2023-6622 kernel: null pointer dereference vulnerability in nft_dynset_init()
In nft_dynset_init(), dynset_expr->ops is checked against set->exprs[i]->ops at (0) and set->exprs[i] may be NULL here. if set->num_exprs == 1, which means set->exprs[1] is NULL, and i == 1, the check at (1) will be passed and set->exprs[1] will be accessed, causing a kernel crash.
Refer:
https://github.com/torvalds/linux/commit/3701cd390fd731ee7ae8b8006246c8db82c72bea
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2253633]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Bugzilla
CVE-2023-46862 kernel: NULL pointer dereference vulnerability in io_uring_show_fdinfo
bugzilla·2023-10-30·CVSS 4.7
CVE-2023-46862 [MEDIUM] CVE-2023-46862 kernel: NULL pointer dereference vulnerability in io_uring_show_fdinfo
CVE-2023-46862 kernel: NULL pointer dereference vulnerability in io_uring_show_fdinfo
An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur.
https://github.com/torvalds/linux/commit/7644b1a1c9a7ae8ab99175989bfc8676055edb46
https://bugzilla.kernel.org/show_bug.cgi?id=218032#c4
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2251043]
---
This was fixed for Fedora with the 6.5.10 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
Bugzilla
CVE-2023-45863 kernel: lib/kobject.c vulnerable to fill_kobj_path out-of-bounds write
bugzilla·2023-10-17·CVSS 6.4
CVE-2023-45863 [MEDIUM] CVE-2023-45863 kernel: lib/kobject.c vulnerable to fill_kobj_path out-of-bounds write
CVE-2023-45863 kernel: lib/kobject.c vulnerable to fill_kobj_path out-of-bounds write
CVE-2023-45863
---
An issue was discovered in lib/kobject.c in the Linux kernel before 6.2.3. With root access, an attacker can trigger a race condition that results in a fill_kobj_path out-of-bounds write.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3bb2a01caa813d3a1845d378bbe4169ef280d394
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.3
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2244721]
---
This was fixed for Fedora with the 6.2.3 stable kernel updates
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
Bugzilla
CVE-2023-42756 kernel: netfilter: race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP
bugzilla·2023-09-20·CVSS 4.7
CVE-2023-42756 [MEDIUM] CVE-2023-42756 kernel: netfilter: race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP
CVE-2023-42756 kernel: netfilter: race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP
A flaw was found under netfilter subsystem. Race between IPSET_CMD_ADD and IPSET_CMD_SWAP. No lock is hold when it does the `cond_resched()`. As a result, `ip_set_ref_lock` (in thread 2) can swap the set with another when thread 1 is doing the `cond_resched()`. Which might lead to a local Denial of Service (DoS).
Discussion:
Reference:
https://seclists.org/oss-sec/2023/q3/242
Upstream fix:
https://github.com/torvalds/linux/commit/7433b6d2afd512d04398c73aa984d1e285be125b
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2241163]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/R
Bugzilla
CVE-2023-42754 kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach()
bugzilla·2023-09-20·CVSS 5.5
CVE-2023-42754 [MEDIUM] CVE-2023-42754 kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach()
CVE-2023-42754 kernel: ipv4: NULL pointer dereference in ipv4_send_dest_unreach()
A flaw was found in ipv4_send_dest_unreach() due to NULL pointer derefence due to a missing edge-case check.
Discussion:
Reference:
https://seclists.org/oss-sec/2023/q4/14
Upstream fix:
https://github.com/torvalds/linux/commit/0113d9c9d1ccc07f5a3710dac4aa24b6d711278c
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2242284]
---
*** Bug 2267759 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redha
Bugzilla
CVE-2023-39194 kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match()
bugzilla·2023-07-26·CVSS 4.4
CVE-2023-39194 [MEDIUM] CVE-2023-39194 kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match()
CVE-2023-39194 kernel: xfrm: out-of-bounds read in __xfrm_state_filter_match()
An out-of-bounds read issue was found in the __xfrm_state_filter_match() function within the XFRM subsystem of the Linux kernel. This flaw requires CAP_NET_ADMIN to be exploited and could lead to information disclosure.
Discussion:
ZDI security advisory:
https://www.zerodayinitiative.com/advisories/ZDI-CAN-18111/
Upstream fix:
https://github.com/torvalds/linux/commit/dfa73c17d55b921e1d4e154976de35317e43a93a
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2242892]
---
This was fixed for Fedora with the 6.4.12 stable kernels
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:239
Bugzilla
CVE-2023-39189 kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one()
bugzilla·2023-07-26·CVSS 6.0
CVE-2023-39189 [MEDIUM] CVE-2023-39189 kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one()
CVE-2023-39189 kernel: netfilter: nftables out-of-bounds read in nf_osf_match_one()
An out-of-bounds read issue was found in the Linux kernel in the nf_osf_match_one() function, which is used for nftables OS fingerprinting. This flaw requires CAP_NET_ADMIN to be exploited and could lead to information disclosure.
Discussion:
Upstream fix:
https://github.com/torvalds/linux/commit/f4f8a7803119005e87b716874bec07c751efafec
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2242893]
---
This was fixed for Fedora with the 6.5.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following produc
Bugzilla
CVE-2023-39193 kernel: netfilter: xtables sctp out-of-bounds read in match_flags()
bugzilla·2023-07-26·CVSS 6.0
CVE-2023-39193 [MEDIUM] CVE-2023-39193 kernel: netfilter: xtables sctp out-of-bounds read in match_flags()
CVE-2023-39193 kernel: netfilter: xtables sctp out-of-bounds read in match_flags()
An out-of-bounds read issue was found in the Linux kernel in the match_flags() function, which belongs to the Xtables SCTP protocol packet matching. This flaw requires CAP_NET_ADMIN to be exploited and could lead to information disclosure.
Discussion:
ZDI security advisory:
https://www.zerodayinitiative.com/advisories/ZDI-CAN-18866/
Upstream fix:
https://github.com/torvalds/linux/commit/e99476497687ef9e850748fe6d232264f30bc8f9
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2242879]
---
This was fixed for Fedora with the 6.5.3 stable kernels
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.c
Bugzilla
CVE-2023-4133 kernel: cxgb4: use-after-free in ch_flower_stats_cb()
bugzilla·2023-07-10·CVSS 5.5
CVE-2023-4133 [MEDIUM] CVE-2023-4133 kernel: cxgb4: use-after-free in ch_flower_stats_cb()
CVE-2023-4133 kernel: cxgb4: use-after-free in ch_flower_stats_cb()
From the upstream fix below: The flower_stats_timer can schedule flower_stats_work and flower_stats_work can also arm the flower_stats_timer [..] When the cxgb4 device is detaching, the timer and workqueue could still be rearmed. As a result, a possible use-after-free bug could happen.
Upstream commit:
https://github.com/torvalds/linux/commit/e50b9b9e8610d47b7c22529443e45a16b1ea3a15
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2228787]
---
This was fixed for Fedora with the 6.2.13 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has
Bugzilla
CVE-2023-6176 kernel: local dos vulnerability in scatterwalk_copychunks
bugzilla·2023-07-03·CVSS 4.7
CVE-2023-6176 [MEDIUM] CVE-2023-6176 kernel: local dos vulnerability in scatterwalk_copychunks
CVE-2023-6176 kernel: local dos vulnerability in scatterwalk_copychunks
When the attacker carefully constructs the network packet to reach the above path, it will execute scatterwalk_copychunks(walk->src.virt.addr, &walk->in, bsize, 0); At this time, the calculated address is 0xdffffc0000000001, which is an invalid kernel address. Accessing this address will panic the kernel, bringing the system crash.
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2250069]
---
This was fixed for Fedora with the 6.5.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Ha
Bugzilla
CVE-2023-39198 kernel: QXL: race condition leading to use-after-free in qxl_mode_dumb_create()
bugzilla·2023-06-28·CVSS 6.4
CVE-2023-39198 [MEDIUM] CVE-2023-39198 kernel: QXL: race condition leading to use-after-free in qxl_mode_dumb_create()
CVE-2023-39198 kernel: QXL: race condition leading to use-after-free in qxl_mode_dumb_create()
A race condition leading to a use-after-free issue was found in the QXL driver in the Linux kernel.
Discussion:
Upstream fix:
https://github.com/torvalds/linux/commit/c611589b4259ed63b9b77be6872b1ce07ec0ac16
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2248704]
---
This was fixed for Fedora with the 6.4.12 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.com/errata/RHSA-2024:2950
---
This issue ha
Bugzilla
CVE-2023-31083 kernel: race condition between HCIUARTSETPROTO and HCIUARTGETPROTO in hci_uart_tty_ioctl
bugzilla·2023-06-07·CVSS 4.7
CVE-2023-31083 [MEDIUM] CVE-2023-31083 kernel: race condition between HCIUARTSETPROTO and HCIUARTGETPROTO in hci_uart_tty_ioctl
CVE-2023-31083 kernel: race condition between HCIUARTSETPROTO and HCIUARTGETPROTO in hci_uart_tty_ioctl
A flaw in the Linux Kernel found in drivers/bluetooth/hci_ldisc.c. There is a race condition between HCIUARTSETPROTO and HCIUARTGETPROTO. HCI_UART_PROTO_SET is set before hu->proto is set. A NULL pointer dereference may occur.
Reference:
https://lore.kernel.org/all/CA+UBctC3p49aTgzbVgkSZ2+TQcqq4fPDO7yZitFT5uBPDeCO2g@mail.gmail.com/
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2213133]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2
Bugzilla
CVE-2023-28866 kernel: Bluetooth: HCI: global out-of-bounds access in net/bluetooth/hci_sync.c
bugzilla·2023-04-10·CVSS 5.3
CVE-2023-28866 [MEDIUM] CVE-2023-28866 kernel: Bluetooth: HCI: global out-of-bounds access in net/bluetooth/hci_sync.c
CVE-2023-28866 kernel: Bluetooth: HCI: global out-of-bounds access in net/bluetooth/hci_sync.c
In the Linux kernel through 6.2.8, net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init2[] are supposed to have an intentionally invalid element, but do not.
https://lore.kernel.org/lkml/[email protected]/
https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=95084403f8c070ccf5d7cbe72352519c1798a40a
https://patchwork.kernel.org/project/bluetooth/patch/[email protected]
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
Bugzilla
CVE-2022-45934 kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c
bugzilla·2022-12-08·CVSS 7.8
CVE-2022-45934 [HIGH] CVE-2022-45934 kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c
CVE-2022-45934 kernel: integer overflow in l2cap_config_req() in net/bluetooth/l2cap_core.c
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
Reference and upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=ae4569813a6e931258db627cdfe50dfb4f917d5d
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2151960]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:2394 https://access.redhat.com/errata/RHSA-2024:2394
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:2950 https://access.redhat.
2024-03-12
Published