Lucene search

K
osvGoogleOSV:USN-6922-1
HistoryJul 29, 2024 - 9:54 a.m.

linux-nvidia-6.5 vulnerabilities

2024-07-2909:54:35
Google
osv.dev
6
linux
kernel
bluetooth
ubi
flash device
vulnerabilities
race condition
debugfs
denial of service
local attacker
cve-2024-24857
cve-2024-24858
cve-2024-24859
unsorted block images
chenyuan yang
logical eraseblock sizes
system crash

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

7.8

Confidence

High

It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel when modifying certain settings values through debugfs.
A privileged local attacker could use this to cause a denial of service.
(CVE-2024-24857, CVE-2024-24858, CVE-2024-24859)

Chenyuan Yang discovered that the Unsorted Block Images (UBI) flash device
volume management subsystem did not properly validate logical eraseblock
sizes in certain situations. An attacker could possibly use this to cause a
denial of service (system crash). (CVE-2024-25739)

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

AI Score

7.8

Confidence

High