CVE-2024-7001
published 2024-08-06CVE-2024-7001: Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.44%
36.4th percentile
Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 127.0.6533.88-1~deb12u1 | 127.0.6533.88-1~deb12u1 |
| chromium | chromium | >= 0 < 127.0.6533.88-1 | 127.0.6533.88-1 |
| chromium | chromium | >= 0 < 127.0.6533.88-1 | 127.0.6533.88-1 |
| debian | chromium | < chromium 127.0.6533.88-1~deb12u1 (bookworm) | chromium 127.0.6533.88-1~deb12u1 (bookworm) |
| chrome | < 127.0.6533.72 | 127.0.6533.72 | |
| chrome | >= 127.0.6533.72 < 127.0.6533.72 | 127.0.6533.72 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv7.5HIGH
vendor_redhat5.5MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: afs: Fix lock recursion
vendor_redhat·2024-11-21·CVSS 5.5
CVE-2024-53090 [MEDIUM] CWE-674 kernel: afs: Fix lock recursion
kernel: afs: Fix lock recursion
In the Linux kernel, the following vulnerability has been resolved:
afs: Fix lock recursion
afs_wake_up_async_call() can incur lock recursion. The problem is that it
is called from AF_RXRPC whilst holding the ->notify_lock, but it tries to
take a ref on the afs_call struct in order to pass it to a work queue - but
if the afs_call is already queued, we then have an extraneous ref that must
be put... calling afs_put_call() may call back down into AF_RXRPC through
rxrpc_kernel_shutdown_call(), however, which might try taking the
->notify_lock again.
This case isn't very common, however, so defer it to a workqueue. The oops
looks something like:
BUG: spinlock recursion on CPU#0, krxrpcio/7001/1646
lock: 0xffff888141399b30, .magic: dead4ead, .owner: krxrpcio/700
Palo Alto
PAN-SA-2024-0007 Prisma Browser: Monthly Vulnerability Updates
vendor_paloalto·2024-08-14·CVSS 8.8
[HIGH] PAN-SA-2024-0007 Prisma Browser: Monthly Vulnerability Updates
PAN-SA-2024-0007 Prisma Browser: Monthly Vulnerability Updates
Prisma Browser (supersedes Talon Browser) has incorporated the latest upstream Chromium security fixes listed here: - https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop.html - https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_23.html - https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop_30.html - https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop.html CVE CVSS Summary CVE-2024-6772 8.8 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H ) Chromium: Inappropriate implementation in V8. CVE-2024-6773 8.8 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H ) Chromium: Type Confusion in V8. CVE-2024-6774 8.8 ( CVSS:3.1/AV:N/AC:
Chrome
Stable Channel Update for Desktop: CVE-2024-7000
vendor_chrome·2024-07-23·CVSS 8.8
CVE-2024-7000 [MEDIUM] Stable Channel Update for Desktop: CVE-2024-7000
Stable Channel Update for Desktop
CVE-2024-7000: Use after free in CSS. Reported by Anonymous on 2024-05-11 [TBD][ 347509736 ] Medium CVE-2024-7001: Inappropriate implementation in HTML
Reported by Jake Archibald on 2024-06-17 [$2000][ 338233148 ] Low CVE-2024-7003: Inappropriate implementation in FedCM
Severity: medium
Microsoft
Chromium: CVE-2024-7001 Inappropriate implementation in HTML
vendor_msrc·2024-07-09·CVSS 4.3
CVE-2024-7001 [MEDIUM] Chromium: CVE-2024-7001 Inappropriate implementation in HTML
Chromium: CVE-2024-7001 Inappropriate implementation in HTML
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
Debian
CVE-2024-7001: chromium - Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 all...
vendor_debian·2024·CVSS 4.3
CVE-2024-7001 [MEDIUM] CVE-2024-7001: chromium - Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 all...
Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 127.0.6533.88-1~deb12u1)
bullseye: open
forky: resolved (fixed in 127.0.6533.88-1)
sid: resolved (fixed in 127.0.6533.88-1)
trixie: resolved (fixed in 127.0.6533.88-1)
OSV
libxmltok vulnerabilities
osv·2024-09-17·CVSS 7.5
CVE-2024-45490 libxmltok vulnerabilities
libxmltok vulnerabilities
USN-7001-1 fixed vulnerabilities in xmltol library. This update
provides the corresponding updates for Ubuntu 24.04 LTS.
Original advisory details:
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle certain function calls when a negative input
length was provided. An attacker could use this issue to cause a denial of
service or possibly execute arbitrary code. (CVE-2024-45490)
Shang-Hung Wan discovered that Expat, contained within the xmltok library,
did not properly handle the potential for an integer overflow on 32-bit
platforms. An attacker could use this issue to cause a denial of service
or possibly execute arbitrary code. (CVE-2024-45491)
OSV
CVE-2024-7001: Inappropriate implementation in HTML in Google Chrome prior to 127
osv·2024-08-06·CVSS 4.3
CVE-2024-7001 [MEDIUM] CVE-2024-7001: Inappropriate implementation in HTML in Google Chrome prior to 127
Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
GHSA
GHSA-pqvj-7wmm-mjvv: Inappropriate implementation in HTML in Google Chrome prior to 127
ghsa_unreviewed·2024-08-06
CVE-2024-7001 [MEDIUM] CWE-474 GHSA-pqvj-7wmm-mjvv: Inappropriate implementation in HTML in Google Chrome prior to 127
Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Suricata
ET WEB_SPECIFIC_APPS Possible Oracle Weblogic IIOP/T3 JNDI Injection Attack (CVE-2024-20931)
suricata·2024-02-12·CVSS 7.5
CVE-2024-20931 [HIGH] ET WEB_SPECIFIC_APPS Possible Oracle Weblogic IIOP/T3 JNDI Injection Attack (CVE-2024-20931)
ET WEB_SPECIFIC_APPS Possible Oracle Weblogic IIOP/T3 JNDI Injection Attack (CVE-2024-20931)
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 7001 (msg:"ET WEB_SPECIFIC_APPS Possible Oracle Weblogic IIOP/T3 JNDI Injection Attack (CVE-2024-20931)"; flow:established,to_server; content:"java.naming.factory.initial"; fast_pattern; content:"jmsInitialContextFactory"; within:60; content:"datasource"; within:20; content:"ldap|3a 2f 2f|"; pcre:"/^(\d{1,3}\.){3}\d{1,3}\x3a\d{1,5}\x2f/R"; reference:url,attackerkb.com/topics/GizBcG19y2/cve-2024-20931; reference:cve,2024-20931; classtype:attempted-admin; sid:2050791; rev:1; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2024_02_12, cve CVE_2024_20931, deployment Perimeter, deployment Internal, performance_impact
Exploit-DB
Siklu MultiHaul TG series < 2.0.0 - unauthenticated credential disclosure
exploitdb·2024-03-28
Siklu MultiHaul TG series < 2.0.0 - unauthenticated credential disclosure
Siklu MultiHaul TG series < 2.0.0 - unauthenticated credential disclosure
---
# Exploit Title: Siklu MultiHaul TG series - unauthenticated credential disclosure
# Date: 28-02-2024
# Exploit Author: semaja2
# Vendor Homepage: https://siklu.com/
# Software Link: https://partners.siklu.com/home/frontdoor
# Version: < 2.0.0
# Tested on: 2.0.0
# CVE : None assigned
#
# Instructions
# 1. Perform IPv6 host detect by pinging all host multicast address for interface attached to device
# `ping6 -I en7 -c 2 ff02::1`
# 2. Review IPv6 neighbours and identify target device based on vendor component of MAC address
# `ip -6 neigh show dev en7`
# 3. Execute script
# `python3 tg-getcreds.py fe80::34d9:1337:b33f:7001%en7`
# 4. Enjoy the access
import socket
import sys
import os
address = str(sys.argv[1]
Metasploit
Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)
metasploit·CVSS 7.5
CVE-2024-7399 [HIGH] Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)
Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)
Remote Code Execution in Samsung MagicINFO 9 Server <= 21.1050.0. Remote code execution can be obtained by exploiting the path traversal vulnerability (CVE-2024-7399) in the SWUpdateFileUploader servlet, which can be queried by an unauthenticated user to upload a JSP shell. By default, the application listens on TCP ports 7001 (HTTP) and 7002 (HTTPS) on all network interfaces and runs in the context of NT AUTHORITY\SYSTEM.
Bugzilla
CVE-2024-53090 kernel: afs: Fix lock recursion
bugzilla·2024-11-21·CVSS 5.5
CVE-2024-53090 [MEDIUM] CVE-2024-53090 kernel: afs: Fix lock recursion
CVE-2024-53090 kernel: afs: Fix lock recursion
In the Linux kernel, the following vulnerability has been resolved:
afs: Fix lock recursion
afs_wake_up_async_call() can incur lock recursion. The problem is that it
is called from AF_RXRPC whilst holding the ->notify_lock, but it tries to
take a ref on the afs_call struct in order to pass it to a work queue - but
if the afs_call is already queued, we then have an extraneous ref that must
be put... calling afs_put_call() may call back down into AF_RXRPC through
rxrpc_kernel_shutdown_call(), however, which might try taking the
->notify_lock again.
This case isn't very common, however, so defer it to a workqueue. The oops
looks something like:
BUG: spinlock recursion on CPU#0, krxrpcio/7001/1646
lock: 0xffff888141399b30, .magic: dead4ead, .
Bugzilla
CVE-2024-36939 kernel: nfs: Handle error of rpc_proc_register() in nfs_net_init().
bugzilla·2024-06-03·CVSS 5.5
CVE-2024-36939 [MEDIUM] CVE-2024-36939 kernel: nfs: Handle error of rpc_proc_register() in nfs_net_init().
CVE-2024-36939 kernel: nfs: Handle error of rpc_proc_register() in nfs_net_init().
In the Linux kernel, the following vulnerability has been resolved:
nfs: Handle error of rpc_proc_register() in nfs_net_init().
The Linux kernel CVE team has assigned CVE-2024-36939 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024053043-CVE-2024-36939-8453@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2284629]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
-
Bugzilla
CVE-2021-47289 kernel: ACPI: fix NULL pointer dereference
bugzilla·2024-05-22·CVSS 5.5
CVE-2021-47289 [MEDIUM] CVE-2021-47289 kernel: ACPI: fix NULL pointer dereference
CVE-2021-47289 kernel: ACPI: fix NULL pointer dereference
In the Linux kernel, the following vulnerability has been resolved:
ACPI: fix NULL pointer dereference
The Linux kernel CVE team has assigned CVE-2021-47289 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052122-CVE-2021-47289-7cbb@gregkh/T
Discussion:
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2021-47289 is: SKIP No affected files built, so skip this CVE NO - - unknown (where first YES/NO value means if related sources built).
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat
Bugzilla
CVE-2021-47321 kernel: watchdog: Fix possible use-after-free by calling del_timer_sync()
bugzilla·2024-05-22·CVSS 7.8
CVE-2021-47321 [HIGH] CVE-2021-47321 kernel: watchdog: Fix possible use-after-free by calling del_timer_sync()
CVE-2021-47321 kernel: watchdog: Fix possible use-after-free by calling del_timer_sync()
In the Linux kernel, the following vulnerability has been resolved:
watchdog: Fix possible use-after-free by calling del_timer_sync()
The Linux kernel CVE team has assigned CVE-2021-47321 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052132-CVE-2021-47321-1b9b@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
This issue has been addressed in the following products:
Red Hat Ente
Bugzilla
CVE-2024-35809 kernel: PCI/PM: Drain runtime-idle callbacks before driver removal
bugzilla·2024-05-17·CVSS 4.7
CVE-2024-35809 [MEDIUM] CVE-2024-35809 kernel: PCI/PM: Drain runtime-idle callbacks before driver removal
CVE-2024-35809 kernel: PCI/PM: Drain runtime-idle callbacks before driver removal
In the Linux kernel, the following vulnerability has been resolved:
PCI/PM: Drain runtime-idle callbacks before driver removal
The Linux kernel CVE team has assigned CVE-2024-35809 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051740-CVE-2024-35809-4a4e@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2281218]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
Bugzilla
CVE-2024-26939 kernel: drm/i915/vma: Fix UAF on destroy against retire race
bugzilla·2024-05-01·CVSS 7.0
CVE-2024-26939 [HIGH] CVE-2024-26939 kernel: drm/i915/vma: Fix UAF on destroy against retire race
CVE-2024-26939 kernel: drm/i915/vma: Fix UAF on destroy against retire race
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/vma: Fix UAF on destroy against retire race
The Linux kernel CVE team has assigned CVE-2024-26939 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050124-CVE-2024-26939-5314@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278221]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
This issue
Bugzilla
CVE-2024-27042 kernel: drm/amdgpu: Fix potential out-of-bounds access in 'amdgpu_discovery_reg_base_init()'
bugzilla·2024-05-01
CVE-2024-27042 [MEDIUM] CVE-2024-27042 kernel: drm/amdgpu: Fix potential out-of-bounds access in 'amdgpu_discovery_reg_base_init()'
CVE-2024-27042 kernel: drm/amdgpu: Fix potential out-of-bounds access in 'amdgpu_discovery_reg_base_init()'
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix potential out-of-bounds access in 'amdgpu_discovery_reg_base_init()'
The Linux kernel CVE team has assigned CVE-2024-27042 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024050113-CVE-2024-27042-e812@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2278448]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000
Bugzilla
CVE-2024-26894 kernel: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()
bugzilla·2024-04-17·CVSS 6.0
CVE-2024-26894 [MEDIUM] CVE-2024-26894 kernel: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()
CVE-2024-26894 kernel: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()
In the Linux kernel, the following vulnerability has been resolved:
ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit()
The Linux kernel CVE team has assigned CVE-2024-26894 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024041743-CVE-2024-26894-53ad@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2275662]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata
Bugzilla
CVE-2024-26769 kernel: nvmet-fc: avoid deadlock on delete association path
bugzilla·2024-04-03·CVSS 4.4
CVE-2024-26769 [MEDIUM] CVE-2024-26769 kernel: nvmet-fc: avoid deadlock on delete association path
CVE-2024-26769 kernel: nvmet-fc: avoid deadlock on delete association path
In the Linux kernel, the following vulnerability has been resolved:
nvmet-fc: avoid deadlock on delete association path
The Linux kernel CVE team has assigned CVE-2024-26769 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040307-CVE-2024-26769-e9cc@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273181]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
Bugzilla
CVE-2024-26717 kernel: HID: i2c-hid-of: fix NULL-deref on failed power up
bugzilla·2024-04-03·CVSS 5.5
CVE-2024-26717 [MEDIUM] CVE-2024-26717 kernel: HID: i2c-hid-of: fix NULL-deref on failed power up
CVE-2024-26717 kernel: HID: i2c-hid-of: fix NULL-deref on failed power up
In the Linux kernel, the following vulnerability has been resolved:
HID: i2c-hid-of: fix NULL-deref on failed power up
The Linux kernel CVE team has assigned CVE-2024-26717 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024040344-CVE-2024-26717-0d01@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2273149]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
This issue has
Bugzilla
CVE-2023-52605 kernel: ACPI: extlog: fix NULL pointer dereference check
bugzilla·2024-03-06
CVE-2023-52605 [LOW] CVE-2023-52605 kernel: ACPI: extlog: fix NULL pointer dereference check
CVE-2023-52605 kernel: ACPI: extlog: fix NULL pointer dereference check
In the Linux kernel, the following vulnerability has been resolved:
ACPI: extlog: fix NULL pointer dereference check
The Linux kernel CVE team has assigned CVE-2023-52605 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030647-CVE-2023-52605-292a@gregkh/T
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2268296]
---
This was fixed for Fedora with the 6.7.4 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 ht
Bugzilla
CVE-2021-47101 kernel: asix: fix uninit-value in asix_mdio_read()
bugzilla·2024-03-05·CVSS 7.1
CVE-2021-47101 [HIGH] CVE-2021-47101 kernel: asix: fix uninit-value in asix_mdio_read()
CVE-2021-47101 kernel: asix: fix uninit-value in asix_mdio_read()
In the Linux kernel, the following vulnerability has been resolved:
asix: fix uninit-value in asix_mdio_read()
The Linux kernel CVE team has assigned CVE-2021-47101 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024030415-CVE-2021-47101-f3fa@gregkh/T
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2024:9315 https://acc
Bugzilla
CVE-2024-23848 kernel: use-after-free in cec_queue_msg_fh
bugzilla·2024-01-24·CVSS 5.5
CVE-2024-23848 [MEDIUM] CVE-2024-23848 kernel: use-after-free in cec_queue_msg_fh
CVE-2024-23848 kernel: use-after-free in cec_queue_msg_fh
In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.
https://lore.kernel.org/lkml/e9f42704-2f99-4f2c-ade5-f952e5fd53e5%40xs4all.nl/
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2260039]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/RHSA-2024:7001
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7000 https://access.redhat.com/errata/RHSA-2024:7000
---
This issue has been addressed in the following products:
Red Hat Enterprise L
Bugzilla
CVE-2022-48619 kernel: event code falling outside of a bitmap in input_set_capability() leads to panic
bugzilla·2024-01-12·CVSS 5.5
CVE-2022-48619 [MEDIUM] CVE-2022-48619 kernel: event code falling outside of a bitmap in input_set_capability() leads to panic
CVE-2022-48619 kernel: event code falling outside of a bitmap in input_set_capability() leads to panic
An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the situation in which an event code falls outside of a bitmap.
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.10
https://github.com/torvalds/linux/commit/409353cbe9fe48f6bc196114c442b1cff05a39bc
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 2263748]
---
This was fixed for Fedora with the 5.17.10 stable kernel updates.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:7001 https://access.redhat.com/errata/R
2024-08-06
Published