Bugzilla – Bug 1224750
VUL-0: REJECTED: CVE-2024-27430: kernel: netrom: Fix a data-race around sysctl_netrom_default_path_quality
Last modified: 2024-05-27 08:53:38 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_default_path_quality We need to protect the reader reading sysctl_netrom_default_path_quality because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27430 https://www.cve.org/CVERecord?id=CVE-2024-27430 https://git.kernel.org/stable/c/392eb88416dcbc5f1d61b9a88d79d78dc8b27652 https://git.kernel.org/stable/c/7510b08c5f5ba15983da004b021fc6154eeb4047 https://git.kernel.org/stable/c/7644df766006d4878a556e427e3ecc78c2d5606b https://git.kernel.org/stable/c/7f615232556f3c6e3eeecef96ef2b00d0aa905bb https://git.kernel.org/stable/c/958d6145a6d9ba9e075c921aead8753fb91c9101 https://git.kernel.org/stable/c/bbc21f134b89535d1cf110c5f2b33ac54e5839c4 https://git.kernel.org/stable/c/dec82a8fc45c6ce494c2cb31f001a2aadb132b57 https://git.kernel.org/stable/c/e041df5dc9e68adffcba5499ca28e1252bed6f4b https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27430.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281071
https://www.suse.com/security/cve/CVE-2024-27430.html cvss 5.5
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27430 958d6145a6d9 ("netrom: Fix a data-race around sysctl_netrom_default_path_quality") merged v6.8~19^2~2^2~11 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27430 bsc#1224750 with CVSS 5.5 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport 958d6145a6d9ba9e075c921aead8753fb91c9101 (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport 958d6145a6d9ba9e075c921aead8753fb91c9101 (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport 958d6145a6d9ba9e075c921aead8753fb91c9101 (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport 958d6145a6d9ba9e075c921aead8753fb91c9101 (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052556-REJECTED-649f@gregkh/
(In reply to Andrea Mattiazzo from comment #6) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052556-REJECTED-649f@gregkh/ Assigning back to the security team