Lucene search

K
redosRedosROS-20240823-01
HistoryAug 23, 2024 - 12:00 a.m.

ROS-20240823-01

2024-08-2300:00:00
redos.red-soft.ru
15
kernel
linux
vulnerability
null pointer dereferencing
denial of service
memory reuse
synchronization generator
af_unix
mellanox technologies switch asics
broadcom fullmac driver
f2fs file system
amdgpu
brcmf_notify_escan_complete()
mlxsw_sp_acl_tcam_vregion_rehash()
drm_cvt_mode()
mlxsw_sp_acl_tcam_ventry_activity_get()
unix_stream_recv_urg()
check_kprobe_address_safe()
drm/amd/display
drm_mode_duplicate

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

Vulnerability of amdgpu_ras_get_context() function in drm/amdgpu component of Linux operating system kernel
is related to null pointer dereferencing on drm_cvt_mode() failure. Exploitation of the vulnerability could
allow an attacker to cause a denial of service

Vulnerability of brcmf_notify_escan_complete() function in module
drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Broadcom FullMAC driver of the
of the Linux kernel is related to the reuse of previously freed memory due to competitive access to a
to a resource (race condition). Exploitation of the vulnerability could allow an attacker to cause a denial of
denial of service

Vulnerability in mlxsw_sp_acl_tcam_vregion_rehash() function in module
drivers/net/ethernet/mellanox/mlxsw/spectrum_acl_tcam.c of the Mellanox Technologies Switch ASICs driver of the kernel of the
of the Linux operating system is related to the reuse of previously freed memory. Exploitation
of the vulnerability could allow an attacker to cause a denial of service

Vulnerability of drm_cvt_mode() function in drm/amdgpu/vkms component of Linux kernel is related to
dereferencing a null pointer when drm_cvt_mode() fails. Exploitation of the vulnerability could allow an
an attacker to cause a denial of service

A vulnerability in the drm/amdgpu component of the Linux operating system kernel is associated with certain types of chips,
such as VEGA20, where amdgpu_regs_smc can lead to abnormal access to the null pointer when the
smc_rreg pointer is NULL. Exploitation of the vulnerability could allow an attacker to cause a denial of
service

Vulnerability in the mlxsw_sp_acl_tcam_ventry_activity_get() function in module
drivers/net/ethernet/mellanox/mlxsw/spectrum_acl_tcam.c of the Mellanox Technologies Switch ASICs driver of the kernel of the
of the Linux operating system is related to the reuse of previously freed memory due to the
competitive access to the resource (race condition). Exploitation of the vulnerability could allow an attacker to
cause a denial of service

A vulnerability in the f2fs_read_multi_pages() function in the fs/f2fs/data.c module of the f2fs file system of the kernel of the
of the Linux operating system is related to the reuse of previously freed memory. Exploitation
exploitation of the vulnerability could allow an attacker to affect the confidentiality, integrity, and
availability of protected information

Vulnerability of the unix_stream_recv_urg() function in the net/unix/af_unix.c module of the AF_UNIX sockets implementation of the AF_UNIX kernel of the Linux operating system is related to the reuse of previously freed memory.
of Linux operating system is related to reuse of previously freed memory. Exploitation
exploitation of the vulnerability could allow an attacker to affect the confidentiality, integrity and availability of protected information.
availability of protected information

Vulnerability in the drm/amd/display component of the Linux operating system kernel is related to NULL dereferencing of the synchronization generator.
synchronization generator. Exploitation of the vulnerability could allow an attacker to cause a denial of
denial of service

A vulnerability in the check_kprobe_address_safe() function in the kernel/kprobes.c module of a Linux kernel is related to the reuse of previously freed synchronization generator.
is related to the reuse of previously freed memory. Exploitation of the vulnerability could allow
an attacker to cause a denial of service

Vulnerability of drm_mode_duplicate() function in drm/panel component of Linux kernel is related to
null pointer dereferencing. Exploitation of the vulnerability could allow an attacker to cause a denial of
denial of service

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64kernel-lt< 6.1.94-1UNKNOWN

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High