Bugzilla – Bug 1224756
VUL-0: REJECTED: CVE-2024-27424: kernel: netrom: Fix a data-race around sysctl_netrom_transport_busy_delay
Last modified: 2024-05-27 08:58:09 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_busy_delay We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27424 https://www.cve.org/CVERecord?id=CVE-2024-27424 https://git.kernel.org/stable/c/0a30016e892bccabea30af218782c4b6ce0970af https://git.kernel.org/stable/c/1f60795dcafc97c45984240d442cdc151f825977 https://git.kernel.org/stable/c/43547d8699439a67b78d6bb39015113f7aa360fd https://git.kernel.org/stable/c/4ccad39009e7bd8a03d60a97c87b0327ae812880 https://git.kernel.org/stable/c/5ac337138272d26d6d3d4f71bc5b1a87adf8b24d https://git.kernel.org/stable/c/7782e5e7047cae6b9255ee727c99fc73d77cf773 https://git.kernel.org/stable/c/85f34d352f4b79afd63dd13634b23dafe6b570f9 https://git.kernel.org/stable/c/f3315a6edaec12b461031eab8c98c78111a41f95 https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27424.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281083
https://www.suse.com/security/cve/CVE-2024-27424.html cvss 5.5
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27424 43547d869943 ("netrom: Fix a data-race around sysctl_netrom_transport_busy_delay") merged v6.8~19^2~2^2~5 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27424 bsc#1224756 with CVSS 5.5 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport 43547d8699439a67b78d6bb39015113f7aa360fd (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport 43547d8699439a67b78d6bb39015113f7aa360fd (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport 43547d8699439a67b78d6bb39015113f7aa360fd (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport 43547d8699439a67b78d6bb39015113f7aa360fd (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052555-REJECTED-d176@gregkh/
(In reply to Andrea Mattiazzo from comment #5) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052555-REJECTED-d176@gregkh/ Assigning back to the security team