Bugzilla – Bug 1224761
VUL-0: REJECTED: CVE-2024-27421: kernel: netrom: Fix a data-race around sysctl_netrom_routing_control
Last modified: 2024-05-27 08:56:49 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_routing_control We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27421 https://www.cve.org/CVERecord?id=CVE-2024-27421 https://git.kernel.org/stable/c/4c02b9ccbb11862ee39850b2b285664cd579b039 https://git.kernel.org/stable/c/859175d4bc11af829e2fdd261a7effdaba9b5d8f https://git.kernel.org/stable/c/b5dffcb8f71bdd02a4e5799985b51b12f4eeaf76 https://git.kernel.org/stable/c/b7d33e083f9d5d39445c0a91e7ad4f3e2c47fcb5 https://git.kernel.org/stable/c/c13fbb5902bce848759385986d4833f5b90782c1 https://git.kernel.org/stable/c/c4309e5f8e80584715c814e1d012dbc3eee5a500 https://git.kernel.org/stable/c/d732b83251322ecd3b503e03442247745d6052ce https://git.kernel.org/stable/c/f9c4d42464173b826190fae2283ed1a4bbae0c8b https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27421.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281089
https://www.suse.com/security/cve/CVE-2024-27421.html cvss 5.3
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27421 b5dffcb8f71b ("netrom: Fix a data-race around sysctl_netrom_routing_control") merged v6.8~19^2~2^2~2 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27421 bsc#1224761 with CVSS 5.3 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport b5dffcb8f71bdd02a4e5799985b51b12f4eeaf76 (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport b5dffcb8f71bdd02a4e5799985b51b12f4eeaf76 (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport b5dffcb8f71bdd02a4e5799985b51b12f4eeaf76 (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport b5dffcb8f71bdd02a4e5799985b51b12f4eeaf76 (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052548-REJECTED-6272@gregkh/
(In reply to Andrea Mattiazzo from comment #5) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052548-REJECTED-6272@gregkh/ Assigning back to the security team