Bugzilla – Bug 1224760
VUL-0: REJECTED: CVE-2024-27422: kernel: netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout
Last modified: 2024-05-27 08:57:23 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27422 https://www.cve.org/CVERecord?id=CVE-2024-27422 https://git.kernel.org/stable/c/01d4e3afe257768cd2a45f15a0e57bacf932b140 https://git.kernel.org/stable/c/2309b369fae2d9cdc3c945cd3eaec84eb1958ca3 https://git.kernel.org/stable/c/498f1d6da11ed6d736d655a2db14ee2d9569eecb https://git.kernel.org/stable/c/4eacb242e22e31385a50a393681d0fe4b55ed1e9 https://git.kernel.org/stable/c/6f254abae02abd4a0aca062c1b3812d7e2d8ea94 https://git.kernel.org/stable/c/73426c32e259c767d40613b956d5b80d0c28a9a9 https://git.kernel.org/stable/c/cbba77abb4a553c1f5afac1ba2a0861aa1f13549 https://git.kernel.org/stable/c/f99b494b40431f0ca416859f2345746199398e2b https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27422.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281087
https://www.suse.com/security/cve/CVE-2024-27422.html cvss 5.5
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27422 f99b494b4043 ("netrom: Fix a data-race around sysctl_netrom_transport_no_activity_timeout") merged v6.8~19^2~2^2~3 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27422 bsc#1224760 with CVSS 5.5 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport f99b494b40431f0ca416859f2345746199398e2b (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport f99b494b40431f0ca416859f2345746199398e2b (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport f99b494b40431f0ca416859f2345746199398e2b (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport f99b494b40431f0ca416859f2345746199398e2b (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052511-REJECTED-5b3f@gregkh/
(In reply to Andrea Mattiazzo from comment #6) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052511-REJECTED-5b3f@gregkh/ Assigning back to the security team