In the Linux kernel, the following vulnerability has been resolved:
net: fddi: fix UAF in fza_probe
fp is netdev private data and it cannot be used after free_netdev() call. Using fp after free_netdev() can cause UAF bug. Fix it by moving free_netdev() after error message.
TURBOchannel adapter")
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | May 21, 2024 |
| Ubuntu | — | Upgrade linuxUpgrade linux-azure-5.4Upgrade linux-awsUpgrade linux-azureUpgrade linux-hwe-5.4Upgrade linux-raspiUpgrade linux-azure-fipsUpgrade linux-gcp-fipsUpgrade linux-raspi-5.4Upgrade linux-kvmUpgrade linux-bluefieldUpgrade linux-gcp-5.4Upgrade linux-oracleUpgrade linux-ibmUpgrade linux-fipsUpgrade linux-aws-5.4Upgrade linux-gcpUpgrade linux-gkeopUpgrade linux-aws-fipsUpgrade linux-oracle-5.4 | Nov 19, 2024 | May 21, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub