Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-36885

Опубликовано: 30 мая 2024
Источник: redhat
CVSS3: 4.4

Описание

[REJECTED CVE] A vulnerability has been identified in the Linux kernel's drm/nouveau/firmware module, where enabling SG_DEBUG causes a kernel BUG() in nvkm_firmware_ctor(). This occurs because DMA-allocated memory cannot be converted into memory pages, leading to an invalid scatterlist mapping. An attacker with control over kernel parameters or device initialization could potentially trigger this bug, causing a system crash or denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelOut of support scope
Red Hat Enterprise Linux 7kernelOut of support scope
Red Hat Enterprise Linux 7kernel-rtOut of support scope
Red Hat Enterprise Linux 8kernelFix deferred
Red Hat Enterprise Linux 8kernel-rtFix deferred
Red Hat Enterprise Linux 9kernel-rtAffected
Red Hat Enterprise Linux 9kernelFixedRHSA-2024:931512.11.2024
Red Hat Enterprise Linux 9kernelFixedRHSA-2024:931512.11.2024

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-489
https://bugzilla.redhat.com/show_bug.cgi?id=2284265kernel: drm/nouveau/firmware: Fix SG_DEBUG error with nvkm_firmware_ctor()

4.4 Medium

CVSS3

Связанные уязвимости

ubuntu
больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

nvd
больше 1 года назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

suse-cvrf
больше 1 года назад

Security update for the Linux Kernel

suse-cvrf
больше 1 года назад

Security update for the Linux Kernel

oracle-oval
11 месяцев назад

ELSA-2024-9315: kernel security update (MODERATE)

4.4 Medium

CVSS3