Bugzilla – Bug 1224755
VUL-0: REJECTED: CVE-2024-27425: kernel: netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay
Last modified: 2024-05-27 08:58:31 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27425 https://www.cve.org/CVERecord?id=CVE-2024-27425 https://git.kernel.org/stable/c/33081e0f34899d5325e7c45683dd8dc9cb18b583 https://git.kernel.org/stable/c/34c84e0036a60e7e50ae50b42ed194d8daef8cc9 https://git.kernel.org/stable/c/5deaef2bf56456c71b841e0dfde1bee2fd88c4eb https://git.kernel.org/stable/c/6133a71c75dacea12fcc85838b4455c2055b0f14 https://git.kernel.org/stable/c/7d56ffc51ebd2777ded8dca50d631ee19d97db5c https://git.kernel.org/stable/c/80578681ea274e0a6512bb7515718c206a7b74cf https://git.kernel.org/stable/c/806f462ba9029d41aadf8ec93f2f99c5305deada https://git.kernel.org/stable/c/a22f9194f61ad4f2b6405c7c86bee85eac1befa5 https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27425.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281081
https://www.suse.com/security/cve/CVE-2024-27425.html cvss 5.5
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27425 806f462ba902 ("netrom: Fix a data-race around sysctl_netrom_transport_acknowledge_delay") merged v6.8~19^2~2^2~6 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27425 bsc#1224755 with CVSS 5.5 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport 806f462ba9029d41aadf8ec93f2f99c5305deada (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport 806f462ba9029d41aadf8ec93f2f99c5305deada (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport 806f462ba9029d41aadf8ec93f2f99c5305deada (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport 806f462ba9029d41aadf8ec93f2f99c5305deada (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052519-REJECTED-8040@gregkh/
(In reply to Andrea Mattiazzo from comment #5) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052519-REJECTED-8040@gregkh/ Assigning back to the security team