Bugzilla – Bug 1224758
VUL-0: REJECTED: CVE-2024-27420: kernel: netrom: Fix a data-race around sysctl_netrom_link_fails_count
Last modified: 2024-05-27 08:55:33 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_link_fails_count We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27420 https://www.cve.org/CVERecord?id=CVE-2024-27420 https://git.kernel.org/stable/c/07bbccd1adb56b39eef982b8960d59e3c005c6a1 https://git.kernel.org/stable/c/0b8eb369c182814d817b9449bc9e86bfae4310f9 https://git.kernel.org/stable/c/97a4d8b9f67cc7efe9a0c137e12f6d9e40795bf1 https://git.kernel.org/stable/c/bc76645ebdd01be9b9994dac39685a3d0f6f7985 https://git.kernel.org/stable/c/c558e54f7712b086fbcb611723272a0a4b0d451c https://git.kernel.org/stable/c/cfe0f73fb38a01bce86fe15ef5f750f850f7d3fe https://git.kernel.org/stable/c/cfedde3058bf976f2f292c0a236edd43afcdab57 https://git.kernel.org/stable/c/db364859ce68fb3a52d42cd87a54da3dc42dc1c8 https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27420.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281091
https://www.suse.com/security/cve/CVE-2024-27420.html cvss 5.5
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27420 bc76645ebdd0 ("netrom: Fix a data-race around sysctl_netrom_link_fails_count") merged v6.8~19^2~2^2~1 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27420 bsc#1224758 with CVSS 5.5 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport bc76645ebdd01be9b9994dac39685a3d0f6f7985 (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport bc76645ebdd01be9b9994dac39685a3d0f6f7985 (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport bc76645ebdd01be9b9994dac39685a3d0f6f7985 (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport bc76645ebdd01be9b9994dac39685a3d0f6f7985 (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE-2024-27420 is now rejected: https://lore.kernel.org/linux-cve-announce/2024052518-REJECTED-1b16@gregkh/
(In reply to Andrea Mattiazzo from comment #6) > CVE-2024-27420 is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052518-REJECTED-1b16@gregkh/ Assigning back to the security team