Bugzilla – Bug 1224754
VUL-0: REJECTED: CVE-2024-27427: kernel: netrom: Fix a data-race around sysctl_netrom_transport_timeout
Last modified: 2024-05-27 08:59:16 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27427 https://www.cve.org/CVERecord?id=CVE-2024-27427 https://git.kernel.org/stable/c/291d36d772f5ea5c68a263ee440f2c9eade371c9 https://git.kernel.org/stable/c/500936692ccca8617a955652d1929f079b17a201 https://git.kernel.org/stable/c/5d5c14efc987900509cec465af26608e39ac607c https://git.kernel.org/stable/c/60a7a152abd494ed4f69098cf0f322e6bb140612 https://git.kernel.org/stable/c/7d1e00fc2af3b7c30835d643a3655b7e9ff7cb20 https://git.kernel.org/stable/c/b8006cb0a34aaf85cdd8741f4148fd9c76b351d3 https://git.kernel.org/stable/c/eadec8da4451c2c0897199691184602e4ee497d1 https://git.kernel.org/stable/c/fed835d415766a94fc0246dcebc3af4c03fe9941 https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27427.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281077
https://www.suse.com/security/cve/CVE-2024-27427.html cvss 5.5
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27427 60a7a152abd4 ("netrom: Fix a data-race around sysctl_netrom_transport_timeout") merged v6.8~19^2~2^2~8 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27427 bsc#1224754 with CVSS 5.5 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport 60a7a152abd494ed4f69098cf0f322e6bb140612 (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport 60a7a152abd494ed4f69098cf0f322e6bb140612 (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport 60a7a152abd494ed4f69098cf0f322e6bb140612 (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport 60a7a152abd494ed4f69098cf0f322e6bb140612 (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052558-REJECTED-b952@gregkh/
(In reply to Andrea Mattiazzo from comment #5) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052558-REJECTED-b952@gregkh/ Assigning back to the security team