OESA-2024-1087
Dashboard / Vulnerabilities / OESA-2024-1087
OESA-2024-1087
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): A flaw was found in the Bluetooth subsystem of the Linux kernel. A race condition between the bt_sock_recvmsg() and bt_sock_ioctl() functions could lead to a use-after-free on a socket buffer ("skb"). This flaw allows a local user to cause a denial of service condition or potential code execution.(CVE-2023-51779) An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.(CVE-2023-51780) An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.(CVE-2023-51781) An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition.(CVE-2023-51782) An out-of-bounds read vulnerability was found in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a remote attacker to send a crafted TCP packet, triggering a heap-based buffer overflow that results in kmalloc data being printed and potentially leaked to the kernel ring buffer (dmesg).(CVE-2023-6121)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2024-1087, https://nvd.nist.gov/vuln/detail/CVE-2023-51779, https://nvd.nist.gov/vuln/detail/CVE-2023-51780, https://nvd.nist.gov/vuln/detail/CVE-2023-51781, https://nvd.nist.gov/vuln/detail/CVE-2023-51782, https://nvd.nist.gov/vuln/detail/CVE-2023-6121
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-22.03-LTS-SP2
Affected ranges
Type: ECOSYSTEM
Events:
