OESA-2024-1083
Dashboard / Vulnerabilities / OESA-2024-1083
OESA-2024-1083
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): A flaw was found in the Bluetooth subsystem of the Linux kernel. A race condition between the bt_sock_recvmsg() and bt_sock_ioctl() functions could lead to a use-after-free on a socket buffer ("skb"). This flaw allows a local user to cause a denial of service condition or potential code execution.(CVE-2023-51779) An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.(CVE-2023-51780) An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.(CVE-2023-51781)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1083, https://nvd.nist.gov/vuln/detail/CVE-2023-51779, https://nvd.nist.gov/vuln/detail/CVE-2023-51780, https://nvd.nist.gov/vuln/detail/CVE-2023-51781
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
