跳转到帖子

Red Hat: CVE-2024-0565: kernel: CIFS Filesystem Decryption Improper Input Validation Remote Code Execution Vulnerability in function receive_encrypted_standard of client (Multiple Advisories)

recommended_posts

发布于
  • Members

Red Hat: CVE-2024-0565: kernel: CIFS Filesystem Decryption Improper Input Validation Remote Code Execution Vulnerability in function receive_encrypted_standard of client (Multiple Advisories)

Severity
7
CVSS
(AV:A/AC:H/Au:S/C:C/I:C/A:C)
Published
01/15/2024
Created
03/08/2024
Added
03/07/2024
Modified
12/05/2024

Description

An out-of-bounds memory read flaw was found in receive_encrypted_standard in fs/smb/client/smb2ops.c in the SMB Client sub-component in the Linux Kernel. This issue occurs due to integer underflow on the memcpy length, leading to a denial of service.

Solution(s)

  • redhat-upgrade-kernel
  • redhat-upgrade-kernel-rt

References

  • CVE-2024-0565
  • RHSA-2024:1188
  • RHSA-2024:1404
  • RHSA-2024:1532
  • RHSA-2024:1533
  • RHSA-2024:1607
  • RHSA-2024:1614
  • RHSA-2024:2394
View more
  • 查看数 703
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…