跳转到帖子

Oracle Linux: CVE-2024-36020: ELSA-2024-5101: kernel security update (IMPORTANT) (Multiple Advisories)

recommended_posts

发布于
  • Members

Oracle Linux: CVE-2024-36020: ELSA-2024-5101:kernel security update (IMPORTANT) (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:H/Au:S/C:N/I:N/A:C)
Published
05/30/2024
Created
08/20/2024
Added
08/16/2024
Modified
12/06/2024

Description

In the Linux kernel, the following vulnerability has been resolved: i40e: fix vf may be used uninitialized in this function warning To fix the regression introduced by commit 52424f974bc5, which causes servers hang in very hard to reproduce conditions with resets races. Using two sources for the information is the root cause. In this function before the fix bumping v didn't mean bumping vf pointer. But the code used this variables interchangeably, so stale vf could point to different/not intended vf. Remove redundant "v" variable and iterate via single VF pointer across whole function instead to guarantee VF pointer validity. A flaw was found in the Linux kernel’s Ethernet Controller XL710 family driver. This flaw allows a local user to crash the system.

Solution(s)

  • oracle-linux-upgrade-kernel

References

  • https://attackerkb.com/topics/cve-2024-36020
  • CVE - 2024-36020
  • ELSA-2024-5101
  • ELSA-2024-5363
  • 查看数 699
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…