跳转到帖子

VMware Photon OS: CVE-2024-26749

recommended_posts

发布于
  • Members

VMware Photon OS: CVE-2024-26749

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
04/03/2024
Created
01/21/2025
Added
01/20/2025
Modified
02/04/2025

Description

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: fixed memory use after free at cdns3_gadget_ep_disable() ... cdns3_gadget_ep_free_request(&priv_ep->endpoint, &priv_req->request); list_del_init(&priv_req->list); ... 'priv_req' actually free at cdns3_gadget_ep_free_request(). But list_del_init() use priv_req->list after it. [ 1542.642868][T534] BUG: KFENCE: use-after-free read in __list_del_entry_valid+0x10/0xd4 [ 1542.642868][T534] [ 1542.653162][T534] Use-after-free read at 0x000000009ed0ba99 (in kfence-#3): [ 1542.660311][T534]__list_del_entry_valid+0x10/0xd4 [ 1542.665375][T534]cdns3_gadget_ep_disable+0x1f8/0x388 [cdns3] [ 1542.671571][T534]usb_ep_disable+0x44/0xe4 [ 1542.675948][T534]ffs_func_eps_disable+0x64/0xc8 [ 1542.680839][T534]ffs_func_set_alt+0x74/0x368 [ 1542.685478][T534]ffs_func_disable+0x18/0x28 Move list_del_init() before cdns3_gadget_ep_free_request() to resolve this problem.

Solution(s)

  • vmware-photon_os_update_tdnf

References

  • https://attackerkb.com/topics/cve-2024-26749
  • CVE - 2024-26749
  • 查看数 705
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…