Rewterz
PatchWork APT Threat Actor Group Targeting Pakistan – Active IOCs
September 10, 2024
Rewterz
Multiple IBM Products Vulnerabilities
September 10, 2024

Multiple Linux Kernel Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2024-43846 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a general protection fault. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-43856 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a flaw with call order in dmam_free_coherent. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-43867 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a refcount underflow when calling nouveau_bo_ref() on a nouveau_bo without initializing it. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-43817 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a missing check in virtio_net_hdr_to_skb(). By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-43902 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a NULL pointer dereferences flaw when passing variables to functions. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2022-48913 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a use-after-free flaw in struct blk_trace. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-43880 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a object nesting flaw. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-43882 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a ToCToU flaw between perm check and set-uid/gid usage. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-42290 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a flaw in the handling of runtime power management. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-42287 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a NULL pointer dereference when performing NPIV and FW reset. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-42304 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by a flaw related to the first directory block is a hole. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-42280 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by an use-after-free in hfcmulti_tx(). A local authenticated attacker could exploit this vulnerability to cause a denial of service.

CVE-2024-42285 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by use-after-free related to destroying CM IDs in service RDMA/iwcm. By sending a specially crafted request, a local authenticated attacker could exploit this vulnerability to cause a denial of service condition.

CVE-2024-42316 CVSS:5.5

Linux Kernel is vulnerable to a denial of service, caused by divde-by-zero in vmpressure_calc_level(). A local authenticated attacker could exploit this vulnerability to cause a denial of service.

Impact

  • Denial of Service

Indicators of Compromise

CVE

  • CVE-2024-43846
  • CVE-2024-43856
  • CVE-2024-43867
  • CVE-2024-43817
  • CVE-2024-43902
  • CVE-2022-48913
  • CVE-2024-43880
  • CVE-2024-43882
  • CVE-2024-42290
  • CVE-2024-42287
  • CVE-2024-42304
  • CVE-2024-42280
  • CVE-2024-42285
  • CVE-2024-42316

Affected Vendors

Linux

Affected Products

  • Linux Kernel 5.4
  • Linux Kernel 4.19
  • Linux Kernel 5.10
  • Linux Kernel 5.15
  • Linux Kernel 6.1
  • Linux Kernel 6.6
  • Linux Kernel 6.10

Remediation

Refer to Linux Kernel GIT Repository for patch, upgrade or suggested workaround information.

CVE-2024-43846

CVE-2024-43856

CVE-2024-43867

CVE-2024-43817

CVE-2024-43902

CVE-2022-48913

CVE-2024-43880

CVE-2024-43882

CVE-2024-42290

CVE-2024-42287

CVE-2024-42304

CVE-2024-42280

CVE-2024-42285

CVE-2024-42316