Bug 1224746 (CVE-2024-27429) - VUL-0: REJECTED: CVE-2024-27429: kernel: netrom: Fix a data-race around sysctl_netrom_obsolescence_count_initialiser
Summary: VUL-0: REJECTED: CVE-2024-27429: kernel: netrom: Fix a data-race around sysct...
Status: RESOLVED WONTFIX
Alias: CVE-2024-27429
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/406350/
Whiteboard: CVSSv3.1:SUSE:CVE-2024-27429:5.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2024-05-20 16:24 UTC by SMASH SMASH
Modified: 2024-05-23 13:10 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Michal Hocko 2024-05-20 19:22:48 UTC
There is a batch of similar reports: bug 1224750, bug 1224753, bug 1224754, bug 1224760, bug 1224761, bug 1224762. All of them essentially copying the specific sysctl value by READ_ONCE. I really fail to see how this can have any security implications. For one thing those sysctls can be modified by the root by default but even aside from that let's say that a malicious user would be modifying them on the fly. What could potentially happen even if those values would be a garbage?
Comment 4 Joey Lee 2024-05-21 05:26:54 UTC
https://www.suse.com/security/cve/CVE-2024-27429.html
cvss 5.5
Comment 6 Michal Hocko 2024-05-21 08:40:11 UTC
I have asked about security implications just out of curiosity:
https://lore.kernel.org/all/ZkxdqOUek_MHqIMn@tiehlicka/T/#u
Comment 11 Davide Benini 2024-05-22 10:31:01 UTC
Closing as RESOLVED/WONTFIX.
The claim about the race is correct, but there are no security consequences

Back to the security team
Comment 12 Michal Hocko 2024-05-23 13:10:32 UTC
(In reply to Davide Benini from comment #11)
> Closing as RESOLVED/WONTFIX.
> The claim about the race is correct, but there are no security consequences
> 
> Back to the security team

For reference
https://lore.kernel.org/all/2024051722-CVE-2024-27429-878c@gregkh/T/#m29b69ed0e008e55ce2d9a6ef6f9c8b6ca85917e9