Логотип exploitDog
bind:"CVE-2024-50301" OR bind:"CVE-2024-49974" OR bind:"CVE-2024-50261"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-50301" OR bind:"CVE-2024-49974" OR bind:"CVE-2024-50261"

Количество 89

Количество 89

oracle-oval логотип

ELSA-2025-9580

5 месяцев назад

ELSA-2025-9580: kernel security update (MODERATE)

EPSS: Низкий
github логотип

GHSA-6gx2-28h4-32x9

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: macsec: Fix use-after-free while sending the offloading packet KASAN reports the following UAF. The metadata_dst, which is used to store the SCI value for macsec offload, is already freed by metadata_dst_free() in macsec_free_netdev(), while driver still use it for sending the packet. To fix this issue, dst_release() is used instead to release metadata_dst. So it is not freed instantly in macsec_free_netdev() if still referenced by skb. BUG: KASAN: slab-use-after-free in mlx5e_xmit+0x1e8f/0x4190 [mlx5_core] Read of size 2 at addr ffff88813e42e038 by task kworker/7:2/714 [...] Workqueue: mld mld_ifc_work Call Trace: <TASK> dump_stack_lvl+0x51/0x60 print_report+0xc1/0x600 kasan_report+0xab/0xe0 mlx5e_xmit+0x1e8f/0x4190 [mlx5_core] dev_hard_start_xmit+0x120/0x530 sch_direct_xmit+0x149/0x11e0 __qdisc_run+0x3ad/0x1730 __dev_queue_xmit+0x1196/0x2ed0 vlan_dev_hard_start_xmit+0x32e/0x510 [8021q]...

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2024-10604

около 1 года назад

Уязвимость функции macsec_free_netdev() ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2025:9580

4 месяца назад

Moderate: kernel security update

EPSS: Низкий
github логотип

GHSA-4xwj-gw53-4w3v

около 1 года назад

In the Linux kernel, the following vulnerability has been resolved: NFSD: Limit the number of concurrent async COPY operations Nothing appears to limit the number of concurrent async COPY operations that clients can start. In addition, AFAICT each async COPY can copy an unlimited number of 4MB chunks, so can run for a long time. Thus IMO async COPY can become a DoS vector. Add a restriction mechanism that bounds the number of concurrent background COPY operations. Start simple and try to be fair -- this patch implements a per-namespace limit. An async COPY request that occurs while this limit is exceeded gets NFS4ERR_DELAY. The requesting client can choose to send the request again after a delay or fall back to a traditional read/write style copy. If there is need to make the mechanism more sophisticated, we can visit that in future patches.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2025-04512

около 1 года назад

Уязвимость компонента NFSD ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02154-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 33 for SLE 15 SP4)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02134-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 31 for SLE 15 SP4)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02111-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 32 for SLE 15 SP4)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02110-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 29 for SLE 15 SP4)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02144-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 27 for SLE 15 SP4)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02142-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 26 for SLE 15 SP4)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02140-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 50 for SLE 15 SP3)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02136-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 49 for SLE 15 SP3)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02125-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 28 for SLE 15 SP4)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02101-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 61 for SLE 12 SP5)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02096-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 60 for SLE 12 SP5)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02075-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 59 for SLE 12 SP5)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02171-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP5)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02139-1

5 месяцев назад

Security update for the Linux Kernel (Live Patch 44 for SLE 15 SP3)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2025-9580

ELSA-2025-9580: kernel security update (MODERATE)

5 месяцев назад
github логотип
GHSA-6gx2-28h4-32x9

In the Linux kernel, the following vulnerability has been resolved: macsec: Fix use-after-free while sending the offloading packet KASAN reports the following UAF. The metadata_dst, which is used to store the SCI value for macsec offload, is already freed by metadata_dst_free() in macsec_free_netdev(), while driver still use it for sending the packet. To fix this issue, dst_release() is used instead to release metadata_dst. So it is not freed instantly in macsec_free_netdev() if still referenced by skb. BUG: KASAN: slab-use-after-free in mlx5e_xmit+0x1e8f/0x4190 [mlx5_core] Read of size 2 at addr ffff88813e42e038 by task kworker/7:2/714 [...] Workqueue: mld mld_ifc_work Call Trace: <TASK> dump_stack_lvl+0x51/0x60 print_report+0xc1/0x600 kasan_report+0xab/0xe0 mlx5e_xmit+0x1e8f/0x4190 [mlx5_core] dev_hard_start_xmit+0x120/0x530 sch_direct_xmit+0x149/0x11e0 __qdisc_run+0x3ad/0x1730 __dev_queue_xmit+0x1196/0x2ed0 vlan_dev_hard_start_xmit+0x32e/0x510 [8021q]...

CVSS3: 7.8
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-10604

Уязвимость функции macsec_free_netdev() ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
0%
Низкий
около 1 года назад
rocky логотип
RLSA-2025:9580

Moderate: kernel security update

4 месяца назад
github логотип
GHSA-4xwj-gw53-4w3v

In the Linux kernel, the following vulnerability has been resolved: NFSD: Limit the number of concurrent async COPY operations Nothing appears to limit the number of concurrent async COPY operations that clients can start. In addition, AFAICT each async COPY can copy an unlimited number of 4MB chunks, so can run for a long time. Thus IMO async COPY can become a DoS vector. Add a restriction mechanism that bounds the number of concurrent background COPY operations. Start simple and try to be fair -- this patch implements a per-namespace limit. An async COPY request that occurs while this limit is exceeded gets NFS4ERR_DELAY. The requesting client can choose to send the request again after a delay or fall back to a traditional read/write style copy. If there is need to make the mechanism more sophisticated, we can visit that in future patches.

CVSS3: 5.5
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-04512

Уязвимость компонента NFSD ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:02154-1

Security update for the Linux Kernel (Live Patch 33 for SLE 15 SP4)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02134-1

Security update for the Linux Kernel (Live Patch 31 for SLE 15 SP4)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02111-1

Security update for the Linux Kernel (Live Patch 32 for SLE 15 SP4)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02110-1

Security update for the Linux Kernel (Live Patch 29 for SLE 15 SP4)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02144-1

Security update for the Linux Kernel (Live Patch 27 for SLE 15 SP4)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02142-1

Security update for the Linux Kernel (Live Patch 26 for SLE 15 SP4)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02140-1

Security update for the Linux Kernel (Live Patch 50 for SLE 15 SP3)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02136-1

Security update for the Linux Kernel (Live Patch 49 for SLE 15 SP3)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02125-1

Security update for the Linux Kernel (Live Patch 28 for SLE 15 SP4)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02101-1

Security update for the Linux Kernel (Live Patch 61 for SLE 12 SP5)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02096-1

Security update for the Linux Kernel (Live Patch 60 for SLE 12 SP5)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02075-1

Security update for the Linux Kernel (Live Patch 59 for SLE 12 SP5)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02171-1

Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP5)

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02139-1

Security update for the Linux Kernel (Live Patch 44 for SLE 15 SP3)

5 месяцев назад

Уязвимостей на страницу