Bugzilla – Bug 1224752
VUL-0: REJECTED: CVE-2024-27428: kernel: netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser
Last modified: 2024-05-27 08:59:33 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27428 https://www.cve.org/CVERecord?id=CVE-2024-27428 https://git.kernel.org/stable/c/119cae5ea3f9e35cdada8e572cc067f072fa825a https://git.kernel.org/stable/c/5731369af2de21695fe7c1c91fe134fabe5b33b8 https://git.kernel.org/stable/c/775ed3549819f814a6ecef5726d2b4c23f249b77 https://git.kernel.org/stable/c/a47d68d777b41862757b7e3051f2d46d6e25f87b https://git.kernel.org/stable/c/acc653e8a3aaab1b7103f98645f2cce7be89e3d3 https://git.kernel.org/stable/c/d1261bde59a3a087ab0c81181821e194278d9264 https://git.kernel.org/stable/c/dca1d93fe42fb9c42b66f61714fbdc55c87eb002 https://git.kernel.org/stable/c/eda02a0bed550f07a8283d3e1f25b90a38e151ed https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27428.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281075
https://www.suse.com/security/cve/CVE-2024-27428.html cvss 5.5
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27428 119cae5ea3f9 ("netrom: Fix data-races around sysctl_netrom_network_ttl_initialiser") merged v6.8~19^2~2^2~9 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27428 bsc#1224752 with CVSS 5.5 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport 119cae5ea3f9e35cdada8e572cc067f072fa825a (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport 119cae5ea3f9e35cdada8e572cc067f072fa825a (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport 119cae5ea3f9e35cdada8e572cc067f072fa825a (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport 119cae5ea3f9e35cdada8e572cc067f072fa825a (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052521-REJECTED-4244@gregkh/
(In reply to Andrea Mattiazzo from comment #5) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052521-REJECTED-4244@gregkh/ Assigning back to the security team