Bugzilla – Bug 1224753
VUL-0: REJECTED: CVE-2024-27426: kernel: netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries
Last modified: 2024-05-27 08:58:56 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27426 https://www.cve.org/CVERecord?id=CVE-2024-27426 https://git.kernel.org/stable/c/34a164d2448264b62af82bc0af3d2c83d12d38ac https://git.kernel.org/stable/c/42e71408e2c138be9ccce60920bd6cf094ba1e32 https://git.kernel.org/stable/c/84b8486e9cedc93875f251ba31abcf73bd586a3a https://git.kernel.org/stable/c/d28fa5f0e6c1554e2829f73a6a276c9a49689d04 https://git.kernel.org/stable/c/e799299aafed417cc1f32adccb2a0e5268b3f6d5 https://git.kernel.org/stable/c/f716a68234242f95305dffb5c9426caa64b316b0 https://git.kernel.org/stable/c/f84f7709486d8a578ab4b7d2a556d1b1a59cfc97 https://git.kernel.org/stable/c/fa3f3ab5c399852d32a0c3cbb8c55882f7e2c61f https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27426.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281079
https://www.suse.com/security/cve/CVE-2024-27426.html cvss 5.5
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27426 e799299aafed ("netrom: Fix a data-race around sysctl_netrom_transport_maximum_tries") merged v6.8~19^2~2^2~7 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27426 bsc#1224753 with CVSS 5.5 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport e799299aafed417cc1f32adccb2a0e5268b3f6d5 (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport e799299aafed417cc1f32adccb2a0e5268b3f6d5 (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport e799299aafed417cc1f32adccb2a0e5268b3f6d5 (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport e799299aafed417cc1f32adccb2a0e5268b3f6d5 (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052538-REJECTED-0b5b@gregkh/
(In reply to Andrea Mattiazzo from comment #5) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052538-REJECTED-0b5b@gregkh/ Assigning back to the security team