In the Linux kernel, the following vulnerability has been resolved:
phonet/pep: refuse to enable an unbound pipe
This ioctl() implicitly assumed that the socket was already bound to a valid local socket name, i.e. Phonet object. If the socket was not bound, two separate problems would occur:
1) We'd send an pipe enablement request with an invalid source object. 2) Later socket calls could BUG on the socket unexpectedly being connected yet not bound to a valid object.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Mar 4, 2024 |
| Ubuntu | — | Upgrade linux-image-genericUpgrade linux-image-awsUpgrade linux-image-4.4.0-1139-awsUpgrade linux-image-4.4.0-1177-awsUpgrade linux-image-virtual-lts-xenialUpgrade linux-image-kvmUpgrade linux-image-4.4.0-262-lowlatencyUpgrade linux-image-4.4.0-1140-kvmUpgrade linux-image-4.4.0-262-genericUpgrade linux-image-lowlatencyUpgrade linux-image-virtualUpgrade linux-image-generic-lts-xenialUpgrade linux-image-lowlatency-lts-xenial | Nov 19, 2024 | Mar 4, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 4, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub