Risk | Critical |
Patch available | YES |
Number of vulnerabilities | 22 |
CVE-ID | CVE-2023-52610 CVE-2024-26773 CVE-2024-26583 CVE-2024-26585 CVE-2024-35852 CVE-2024-26686 CVE-2022-48627 CVE-2024-26870 CVE-2024-26584 CVE-2023-52448 CVE-2024-36886 CVE-2024-26733 CVE-2024-38538 CVE-2024-35910 CVE-2024-36020 CVE-2024-38555 CVE-2024-36971 CVE-2024-26704 CVE-2024-26982 CVE-2024-26640 CVE-2023-20569 CVE-2024-36000 |
CWE-ID | CWE-401 CWE-667 CWE-362 CWE-400 CWE-119 CWE-388 CWE-476 CWE-416 CWE-908 CWE-415 CWE-20 CWE-399 CWE-200 CWE-617 |
Exploitation vector | Network |
Public exploit | Vulnerability #17 is being exploited in the wild. |
Vulnerable software Subscribe |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for Power, little endian - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for IBM z Systems - Extended Update Support Operating systems & Components / Operating system Red Hat Enterprise Linux for x86_64 - Extended Update Support Operating systems & Components / Operating system kernel (Red Hat package) Operating systems & Components / Operating system package or component |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 22 vulnerabilities.
EUVDB-ID: #VU89382
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52610
CWE-ID:
CWE-401 - Missing release of memory after effective lifetime
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform DoS attack on the target system.
The vulnerability exists due memory leak in net/sched/act_ct.c. A local user can force the kernel to leak memory and perform denial of service attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU93787
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26773
CWE-ID:
CWE-667 - Improper Locking
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the ext4_mb_try_best_found() function in fs/ext4/mballoc.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87596
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26583
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a race condition between async notify and socket close in TLS implementation in net/tls/tls_sw.c. A remote attacker can send specially crafted traffic to the system, trigger a race condition and perform a denial of service (DoS) attack.
Install updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89251
Risk: Medium
CVSSv3.1: 5.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26585
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a race condition within the tls_encrypt_done() function in net/tls/tls_sw.c. A remote attacker user can send specially crafted requests to the system and perform a denial of service (DoS) attack.
Install updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89983
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-35852
CWE-ID:
CWE-401 - Missing release of memory after effective lifetime
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the mlxsw_sp_acl_tcam_vregion_destroy() function in drivers/net/ethernet/mellanox/mlxsw/spectrum_acl_tcam.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU91530
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26686
CWE-ID:
CWE-667 - Improper Locking
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the do_task_stat() function in fs/proc/array.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU92194
Risk: Low
CVSSv3.1: 3.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2022-48627
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU92006
Risk: Low
CVSSv3.1: 7.7 [AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26870
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the nfs4_listxattr() function in fs/nfs/nfs4proc.c. A local user can escalate privileges on the system.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89001
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26584
CWE-ID:
CWE-388 - Error Handling
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when handling backlogging of crypto requests in net/tls/tls_sw.c. A remote attacker can send specially crafted traffic to the system and perform a denial of service attack.
Install updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87741
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52448
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in gfs2_rgrp_dump() function. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU90049
Risk: High
CVSSv3.1: 7.8 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-36886
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a use-after-free error within the tipc_buf_append() function in net/tipc/msg.c when processing fragmented TIPC messages. A remote attacker can send specially crafted packets to the system, trigger a use-after-free error and execute arbitrary code on the system in the context of the kernel.
Install updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU92952
Risk: Low
CVSSv3.1: 7.7 [AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26733
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the arp_req_get() function in net/ipv4/arp.c. A local user can escalate privileges on the system.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU92373
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-38538
CWE-ID:
CWE-908 - Use of Uninitialized Resource
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the EXPORT_SYMBOL_GPL() and br_dev_xmit() functions in net/bridge/br_device.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU92021
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-35910
CWE-ID:
CWE-667 - Improper Locking
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the tcp_close() function in net/ipv4/tcp.c, within the inet_csk_clear_xmit_timers() function in net/ipv4/inet_connection_sock.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU91675
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-36020
CWE-ID:
CWE-908 - Use of Uninitialized Resource
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to use of uninitialized resource within the i40e_reset_all_vfs() function in drivers/net/ethernet/intel/i40e/i40e_virtchnl_pf.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU92307
Risk: Low
CVSSv3.1: 7.7 [AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-38555
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the cmd_comp_notifier() function in drivers/net/ethernet/mellanox/mlx5/core/cmd.c. A local user can escalate privileges on the system.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU91597
Risk: Critical
CVSSv3.1: 8.4 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C]
CVE-ID: CVE-2024-36971
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a use-after-free error within the xfrm_link_failure() function in net/xfrm/xfrm_policy.c, within the dst_entry ip6_dst_check() and ip6_dst_check() functions in net/ipv6/route.c, within the dst_entry ipv4_dst_check() and ip_do_redirect() functions in net/ipv4/route.c. A remote attacker can send specially crafted packets to the system and execute arbitrary code.
Note, the vulnerability is being actively exploited in the wild.
Install updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
Yes. This vulnerability is being exploited in the wild.
EUVDB-ID: #VU90929
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26704
CWE-ID:
CWE-415 - Double Free
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a double free error within the ext4_move_extents() function in fs/ext4/move_extent.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU90857
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26982
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the squashfs_new_inode() function in fs/squashfs/inode.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89397
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26640
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the skb_advance_to_frag() function in net/ipv4/tcp.c. A remote attacker can send specially crafted data to the system and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU79263
Risk: Low
CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-20569
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to a side channel issue in AMD CPUs. A remote user can influence the return address prediction and gain unauthorized access to sensitive information on the system.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU90907
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-36000
CWE-ID:
CWE-617 - Reachable Assertion
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to reachable assertion within the alloc_huge_page() function in mm/hugetlb.c. A local user can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.8
Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.8
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.8
Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.8
kernel (Red Hat package): before 4.18.0-477.67.1.el8_8
CPE2.3http://access.redhat.com/errata/RHSA-2024:5255
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.