In the Linux kernel, the following vulnerability has been resolved:
net: lantiq: fix memory corruption in RX ring
In a situation where memory allocation or dma mapping fails, an invalid address is programmed into the descriptor. This can lead to memory corruption. If the memory allocation fails, DMA should reuse the previous skb and mapping and drop the packet. This patch also increments rx drop counter.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Mar 25, 2024 |
| Suse | — | Upgrade kernel-64kb-develUpgrade kernel-defaultUpgrade reiserfs-kmp-defaultUpgrade kernel-symsUpgrade kernel-default-develUpgrade kernel-develUpgrade kernel-docsUpgrade kernel-default-baseUpgrade kernel-64kbUpgrade kernel-preempt-develUpgrade kernel-macrosUpgrade kernel-obs-buildUpgrade kernel-sourceUpgrade kernel-zfcpdumpUpgrade kernel-preempt | Aug 9, 2024 | Mar 25, 2024 |
| Ubuntu | — | Upgrade linux-raspi-5.4Upgrade linux-oracle-5.4Upgrade linux-gcp-5.4Upgrade linux-aws-fipsUpgrade linux-bluefieldUpgrade linux-gcpUpgrade linux-oracleUpgrade linux-fipsUpgrade linux-kvmUpgrade linux-azure-fipsUpgrade linux-gcp-fipsUpgrade linux-raspiUpgrade linuxUpgrade linux-awsUpgrade linux-azure-5.4Upgrade linux-hwe-5.4Upgrade linux-aws-5.4Upgrade linux-azureUpgrade linux-gkeop | Nov 19, 2024 | Mar 25, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub