PatchWork APT Threat Actor Group Targeting Pakistan – Active IOCs
September 10, 2024Multiple IBM Products Vulnerabilities
September 10, 2024PatchWork APT Threat Actor Group Targeting Pakistan – Active IOCs
September 10, 2024Multiple IBM Products Vulnerabilities
September 10, 2024Severity
Medium
Analysis Summary
CVE-2024-43846 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a general protection fault. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-43856 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a flaw with call order in dmam_free_coherent. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-43867 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a refcount underflow when calling nouveau_bo_ref() on a nouveau_bo without initializing it. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-43817 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a missing check in virtio_net_hdr_to_skb(). By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-43902 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a NULL pointer dereferences flaw when passing variables to functions. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2022-48913 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a use-after-free flaw in struct blk_trace. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-43880 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a object nesting flaw. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-43882 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a ToCToU flaw between perm check and set-uid/gid usage. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-42290 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a flaw in the handling of runtime power management. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-42287 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a NULL pointer dereference when performing NPIV and FW reset. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-42304 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by a flaw related to the first directory block is a hole. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-42280 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by an use-after-free in hfcmulti_tx(). A local authenticated attacker could exploit this vulnerability to cause a denial of service.
CVE-2024-42285 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by use-after-free related to destroying CM IDs in service RDMA/iwcm. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.
CVE-2024-42316 CVSS:5.5
Linux Kernel is vulnerable to a denial of service, caused by divde-by-zero in vmpressure_calc_level(). A local authenticated attacker could exploit this vulnerability to cause a denial of service.
Impact
- Denial of Service
Indicators of Compromise
CVE
- CVE-2024-43846
- CVE-2024-43856
- CVE-2024-43867
- CVE-2024-43817
- CVE-2024-43902
- CVE-2022-48913
- CVE-2024-43880
- CVE-2024-43882
- CVE-2024-42290
- CVE-2024-42287
- CVE-2024-42304
- CVE-2024-42280
- CVE-2024-42285
- CVE-2024-42316
Affected Vendors
Affected Products
- Linux Kernel 5.4
- Linux Kernel 4.19
- Linux Kernel 5.10
- Linux Kernel 5.15
- Linux Kernel 6.1
- Linux Kernel 6.6
- Linux Kernel 6.10
Remediation
Refer to Linux Kernel GIT Repository for patch, upgrade or suggested workaround information.