Rapid7 Vulnerability & Exploit Database

Debian: CVE-2024-44965: linux -- security update

Free InsightVM Trial No Credit Card Necessary
2024 Attack Intel Report Latest research by Rapid7实验室
Back to 搜索

Debian: CVE-2024-44965: linux -- security update

严重程度
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
发表
09/04/2024
创建
09/07/2024
添加
09/06/2024
修改
09/06/2024

描述

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix pti_clone_pgtable() alignment assumption Guenter reported dodgy crashes on an i386-nosmp build using GCC-11 that had the form of endless traps until entry stack exhaust 和 then #DF from the stack guard. It turned out that pti_clone_pgtable() had alignment 假设 on the start address, notably it hard assumes start is PMD aligned. 这 is true on x86_64, but very much not true on i386. These 假设 can cause the end condition to malfunction, leading to a 'short' clone. Guess what happens when the user mapping has a short copy of the entry text? Use the correct increment form for addr to avoid alignment 假设.

解决方案(年代)

  • debian-upgrade-linux

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, 和 what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value 和 insight.

– Scott Cheney, 经理 of Information Security, Sierra View Medical Center

;