Lucene search

K
redosRedosROS-20240924-04
HistorySep 24, 2024 - 12:00 a.m.

ROS-20240924-04

2024-09-2400:00:00
redos.red-soft.ru
1
fastrpc
usb_submit_urb
linux kernel
race conditions
memory release
improper locking
denial of service
drm/virtio
usbtmc
qcom-geni-serial
gadgetfs
smp
gsmi
hdmi
da9211
f_ncm
tty
f2fs
ixgbe
dp_aux_cmd_fifo_tx
synchronization errors

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

Low

A vulnerability in the fastrpc component of the Linux operating system kernel is related to race conditions after a
memory release. Exploitation of the vulnerability could allow an attacker to affect the
confidentiality, integrity, and availability

A vulnerability in the usb_submit_urb() function of the Linux operating system kernel is related to improper locking.
Exploitation of the vulnerability could allow an attacker to cause a denial of service

A vulnerability in the fastrpc component of the Linux operating system kernel is related to memory usage after a
release. Exploitation of the vulnerability could allow an attacker to impact the
confidentiality, integrity and availability

A vulnerability in the drm/virtio component of the Linux kernel is related to the ability to guess the value of the
descriptor and attempt to accelerate the creation of a GEM object using the close descriptor. Exploitation
The vulnerability could allow an attacker to impact the confidentiality, integrity, and availability of the

A vulnerability in the usbtmc component of the Linux operating system kernel is related to errors in the channel direction for the
control transfer. Exploitation of the vulnerability could allow the vulnerability to cause a denial of service

A vulnerability in the qcom-geni-serial component of the Linux operating system kernel is related to an out of bounds
RX FIFO buffer. Exploitation of the vulnerability could allow an attacker to impact the
confidentiality, integrity and availability

A vulnerability in the gadgetfs component of the Linux operating system kernel is related to a race condition between
mounting and unmounting. Exploitation of the vulnerability could allow an attacker to affect the confidentiality, integrity, and availability of the gadgetfs component of the Linux kernel.
confidentiality, integrity, and availability

A vulnerability in the smp component of the Linux operating system kernel is related to resource management errors.
Exploitation of the vulnerability could allow an attacker to cause a denial of service

A vulnerability in the gsmi component of the Linux kernel is related to NULL pointer dereferencing.
Exploitation of the vulnerability may allow an attacker to cause a denial of service

A vulnerability in the hdmi component of the Linux operating system kernel is related to unregistration of a device
codec when unbinding is canceled. Exploitation of the vulnerability may allow an attacker to cause a denial of service

A vulnerability in the da9211 component of the da9211 kernel of a Linux operating system is related to improper locking.
Exploitation of the vulnerability could allow an attacker to cause a denial of service

A vulnerability in the f_ncm component of the Linux kernel is related to dereferencing of NULL ptr in the
ncm_bitrate(). Exploitation of the vulnerability could allow an attacker to cause a denial of service

A vulnerability in the tty component of the Linux kernel is related to NULL pointer dereferencing.
Exploitation of the vulnerability could allow an attacker to cause a denial of service

A vulnerability in the f2fs component of the Linux kernel is associated with a panic state if extend_tree
is not created. Exploitation of the vulnerability may allow an attacker to cause a denial of service

A vulnerability in the ixgbe component of the Linux operating system kernel is associated with reference counter leaks
of a PCI device. Exploitation of the vulnerability could allow an attacker to cause a denial of service

Vulnerability in the dp_aux_cmd_fifo_tx() function of the dp component of the Linux kernel is related to synchronization errors when using a shared resource.
synchronization errors when using a shared resource. Exploitation of the vulnerability could allow an attacker to
to impact confidentiality, integrity, and availability.

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64kernel-lt< 6.1.94-1UNKNOWN

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

Low