![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2024-36915 |
Description: | In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies syzbot reported
unsafe calls to copy_from_sockptr() [1] Use copy_safe_from_sockptr()
instead. [1] BUG: KASAN: slab-out-of-bounds in
copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG:
KASAN: slab-out-of-bounds in copy_from_sockptr
include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in
nfc_llcp_setsockopt+0x6c2/0x850 net/nfc/llcp_sock.c:255 Read of size 4
at addr ffff88801caa1ec3 by task syz-executor459/5078 CPU: 0 PID: 5078
Comm: syz-executor459 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e
#0 Hardware name: Google Google Compute Engine/Google Compute Engine,
BIOS Google 03/27/2024 Call Trace: |
Test IDs: | None available |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2024-36915 https://git.kernel.org/stable/c/29dc0ea979d433dd3c26abc8fa971550bdc05107 https://git.kernel.org/stable/c/29dc0ea979d433dd3c26abc8fa971550bdc05107 https://git.kernel.org/stable/c/7a87441c9651ba37842f4809224aca13a554a26f https://git.kernel.org/stable/c/7a87441c9651ba37842f4809224aca13a554a26f |