跳转到帖子

Ubuntu: (Multiple Advisories) (CVE-2024-36016): Linux kernel vulnerabilities

recommended_posts

发布于
  • Members

Ubuntu: (Multiple Advisories) (CVE-2024-36016): Linux kernel vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
05/29/2024
Created
07/31/2024
Added
07/31/2024
Modified
01/23/2025

Description

In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_receive() Assuming the following: - side A configures the n_gsm in basic option mode - side B sends the header of a basic option mode frame with data length 1 - side A switches to advanced option mode - side B sends 2 data bytes which exceeds gsm->len Reason: gsm->len is not used in advanced option mode. - side A switches to basic option mode - side B keeps sending until gsm0_receive() writes past gsm->buf Reason: Neither gsm->state nor gsm->len have been reset after reconfiguration. Fix this by changing gsm->count to gsm->len comparison from equal to less than. Also add upper limit checks against the constant MAX_MRU in gsm0_receive() and gsm1_receive() to harden against memory corruption of gsm->len and gsm->mru. All other checks remain as we still need to limit the data according to the user configuration and actual payload size.

Solution(s)

  • ubuntu-upgrade-linux-image-4-15-0-1133-oracle
  • ubuntu-upgrade-linux-image-4-15-0-1154-kvm
  • ubuntu-upgrade-linux-image-4-15-0-1164-gcp
  • ubuntu-upgrade-linux-image-4-15-0-1170-aws
  • ubuntu-upgrade-linux-image-4-15-0-1179-azure
  • ubuntu-upgrade-linux-image-4-15-0-227-generic
  • ubuntu-upgrade-linux-image-4-15-0-227-lowlatency
  • ubuntu-upgrade-linux-image-4-4-0-1134-aws
  • ubuntu-upgrade-linux-image-4-4-0-1135-kvm
  • ubuntu-upgrade-linux-image-4-4-0-1172-aws
  • ubuntu-upgrade-linux-image-4-4-0-257-generic
  • ubuntu-upgrade-linux-image-4-4-0-257-lowlatency
  • ubuntu-upgrade-linux-image-5-15-0-1035-xilinx-zynqmp
  • ubuntu-upgrade-linux-image-5-15-0-1049-gkeop
  • ubuntu-upgrade-linux-image-5-15-0-1059-ibm
  • ubuntu-upgrade-linux-image-5-15-0-1059-raspi
  • ubuntu-upgrade-linux-image-5-15-0-1061-intel-iotg
  • ubuntu-upgrade-linux-image-5-15-0-1061-nvidia
  • ubuntu-upgrade-linux-image-5-15-0-1061-nvidia-lowlatency
  • ubuntu-upgrade-linux-image-5-15-0-1063-gke
  • ubuntu-upgrade-linux-image-5-15-0-1063-kvm
  • ubuntu-upgrade-linux-image-5-15-0-1064-oracle
  • ubuntu-upgrade-linux-image-5-15-0-1065-gcp
  • ubuntu-upgrade-linux-image-5-15-0-1065-oracle
  • ubuntu-upgrade-linux-image-5-15-0-1066-aws
  • ubuntu-upgrade-linux-image-5-15-0-1070-azure
  • ubuntu-upgrade-linux-image-5-15-0-1070-azure-fde
  • ubuntu-upgrade-linux-image-5-15-0-117-generic
  • ubuntu-upgrade-linux-image-5-15-0-117-generic-64k
  • ubuntu-upgrade-linux-image-5-15-0-117-generic-lpae
  • ubuntu-upgrade-linux-image-5-15-0-117-lowlatency
  • ubuntu-upgrade-linux-image-5-15-0-117-lowlatency-64k
  • ubuntu-upgrade-linux-image-5-4-0-1041-iot
  • ubuntu-upgrade-linux-image-5-4-0-1048-xilinx-zynqmp
  • ubuntu-upgrade-linux-image-5-4-0-1076-ibm
  • ubuntu-upgrade-linux-image-5-4-0-1089-bluefield
  • ubuntu-upgrade-linux-image-5-4-0-1096-gkeop
  • ubuntu-upgrade-linux-image-5-4-0-1113-raspi
  • ubuntu-upgrade-linux-image-5-4-0-1114-raspi
  • ubuntu-upgrade-linux-image-5-4-0-1117-kvm
  • ubuntu-upgrade-linux-image-5-4-0-1129-aws
  • ubuntu-upgrade-linux-image-5-4-0-1129-oracle
  • ubuntu-upgrade-linux-image-5-4-0-1133-gcp
  • ubuntu-upgrade-linux-image-5-4-0-1134-azure
  • ubuntu-upgrade-linux-image-5-4-0-190-generic
  • ubuntu-upgrade-linux-image-5-4-0-190-generic-lpae
  • ubuntu-upgrade-linux-image-5-4-0-190-lowlatency
  • ubuntu-upgrade-linux-image-6-8-0-1007-gke
  • ubuntu-upgrade-linux-image-6-8-0-1008-raspi
  • ubuntu-upgrade-linux-image-6-8-0-1009-ibm
  • ubuntu-upgrade-linux-image-6-8-0-1009-oem
  • ubuntu-upgrade-linux-image-6-8-0-1010-nvidia
  • ubuntu-upgrade-linux-image-6-8-0-1010-nvidia-64k
  • ubuntu-upgrade-linux-image-6-8-0-1010-oracle
  • ubuntu-upgrade-linux-image-6-8-0-1010-oracle-64k
  • ubuntu-upgrade-linux-image-6-8-0-1011-gcp
  • ubuntu-upgrade-linux-image-6-8-0-1011-nvidia-lowlatency
  • ubuntu-upgrade-linux-image-6-8-0-1011-nvidia-lowlatency-64k
  • ubuntu-upgrade-linux-image-6-8-0-1012-aws
  • ubuntu-upgrade-linux-image-6-8-0-1012-azure
  • ubuntu-upgrade-linux-image-6-8-0-1012-azure-fde
  • ubuntu-upgrade-linux-image-6-8-0-39-generic
  • ubuntu-upgrade-linux-image-6-8-0-39-generic-64k
  • ubuntu-upgrade-linux-image-6-8-0-39-lowlatency
  • ubuntu-upgrade-linux-image-6-8-0-39-lowlatency-64k
  • ubuntu-upgrade-linux-image-aws
  • ubuntu-upgrade-linux-image-aws-hwe
  • ubuntu-upgrade-linux-image-aws-lts-18-04
  • ubuntu-upgrade-linux-image-aws-lts-20-04
  • ubuntu-upgrade-linux-image-aws-lts-22-04
  • ubuntu-upgrade-linux-image-azure
  • ubuntu-upgrade-linux-image-azure-cvm
  • ubuntu-upgrade-linux-image-azure-fde
  • ubuntu-upgrade-linux-image-azure-fde-lts-22-04
  • ubuntu-upgrade-linux-image-azure-lts-18-04
  • ubuntu-upgrade-linux-image-azure-lts-20-04
  • ubuntu-upgrade-linux-image-azure-lts-22-04
  • ubuntu-upgrade-linux-image-bluefield
  • ubuntu-upgrade-linux-image-gcp
  • ubuntu-upgrade-linux-image-gcp-lts-18-04
  • ubuntu-upgrade-linux-image-gcp-lts-20-04
  • ubuntu-upgrade-linux-image-gcp-lts-22-04
  • ubuntu-upgrade-linux-image-generic
  • ubuntu-upgrade-linux-image-generic-64k
  • ubuntu-upgrade-linux-image-generic-64k-hwe-20-04
  • ubuntu-upgrade-linux-image-generic-64k-hwe-24-04
  • ubuntu-upgrade-linux-image-generic-hwe-16-04
  • ubuntu-upgrade-linux-image-generic-hwe-18-04
  • ubuntu-upgrade-linux-image-generic-hwe-20-04
  • ubuntu-upgrade-linux-image-generic-hwe-24-04
  • ubuntu-upgrade-linux-image-generic-lpae
  • ubuntu-upgrade-linux-image-generic-lpae-hwe-20-04
  • ubuntu-upgrade-linux-image-generic-lts-xenial
  • ubuntu-upgrade-linux-image-gke
  • ubuntu-upgrade-linux-image-gke-5-15
  • ubuntu-upgrade-linux-image-gkeop
  • ubuntu-upgrade-linux-image-gkeop-5-15
  • ubuntu-upgrade-linux-image-gkeop-5-4
  • ubuntu-upgrade-linux-image-ibm
  • ubuntu-upgrade-linux-image-ibm-classic
  • ubuntu-upgrade-linux-image-ibm-lts-20-04
  • ubuntu-upgrade-linux-image-ibm-lts-24-04
  • ubuntu-upgrade-linux-image-intel
  • ubuntu-upgrade-linux-image-intel-iotg
  • ubuntu-upgrade-linux-image-kvm
  • ubuntu-upgrade-linux-image-lowlatency
  • ubuntu-upgrade-linux-image-lowlatency-64k
  • ubuntu-upgrade-linux-image-lowlatency-64k-hwe-20-04
  • ubuntu-upgrade-linux-image-lowlatency-hwe-16-04
  • ubuntu-upgrade-linux-image-lowlatency-hwe-18-04
  • ubuntu-upgrade-linux-image-lowlatency-hwe-20-04
  • ubuntu-upgrade-linux-image-lowlatency-lts-xenial
  • ubuntu-upgrade-linux-image-nvidia
  • ubuntu-upgrade-linux-image-nvidia-64k
  • ubuntu-upgrade-linux-image-nvidia-lowlatency
  • ubuntu-upgrade-linux-image-nvidia-lowlatency-64k
  • ubuntu-upgrade-linux-image-oem
  • ubuntu-upgrade-linux-image-oem-20-04
  • ubuntu-upgrade-linux-image-oem-20-04b
  • ubuntu-upgrade-linux-image-oem-20-04c
  • ubuntu-upgrade-linux-image-oem-20-04d
  • ubuntu-upgrade-linux-image-oem-24-04
  • ubuntu-upgrade-linux-image-oem-24-04a
  • ubuntu-upgrade-linux-image-oem-osp1
  • ubuntu-upgrade-linux-image-oracle
  • ubuntu-upgrade-linux-image-oracle-64k
  • ubuntu-upgrade-linux-image-oracle-lts-18-04
  • ubuntu-upgrade-linux-image-oracle-lts-20-04
  • ubuntu-upgrade-linux-image-oracle-lts-22-04
  • ubuntu-upgrade-linux-image-raspi
  • ubuntu-upgrade-linux-image-raspi-hwe-18-04
  • ubuntu-upgrade-linux-image-raspi-nolpae
  • ubuntu-upgrade-linux-image-raspi2
  • ubuntu-upgrade-linux-image-snapdragon-hwe-18-04
  • ubuntu-upgrade-linux-image-virtual
  • ubuntu-upgrade-linux-image-virtual-hwe-16-04
  • ubuntu-upgrade-linux-image-virtual-hwe-18-04
  • ubuntu-upgrade-linux-image-virtual-hwe-20-04
  • ubuntu-upgrade-linux-image-virtual-hwe-24-04
  • ubuntu-upgrade-linux-image-virtual-lts-xenial
  • ubuntu-upgrade-linux-image-xilinx-zynqmp

References

  • https://attackerkb.com/topics/cve-2024-36016
  • CVE - 2024-36016
  • USN-6921-1
  • USN-6921-2
  • USN-6923-1
  • USN-6923-2
  • USN-6924-1
  • USN-6924-2
  • USN-6926-1
  • USN-6926-2
  • USN-6926-3
  • USN-6927-1
  • USN-6938-1
  • USN-6952-1
  • USN-6952-2
  • USN-6953-1
  • USN-6956-1
  • USN-6957-1
  • USN-6979-1
  • USN-7019-1
View more
  • 查看数 698
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…