Bugzilla – Bug 1224762
VUL-0: REJECTED: CVE-2024-27423: kernel: netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size
Last modified: 2024-05-27 08:57:46 UTC
In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size We need to protect the reader reading the sysctl value because the value can be changed concurrently. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27423 https://www.cve.org/CVERecord?id=CVE-2024-27423 https://git.kernel.org/stable/c/0d43a58900e5a2bfcc9de47e16c6c501c0bef853 https://git.kernel.org/stable/c/46803b776d869b0c36041828a83c4f7da2dfa03b https://git.kernel.org/stable/c/489e05c614dbeb1a1148959f02bdb788891819e6 https://git.kernel.org/stable/c/4f2efa17c3ec5e4be0567b47439b9713c0dc6550 https://git.kernel.org/stable/c/652b0b35819610a42b8a90d21acb12f69943b397 https://git.kernel.org/stable/c/89aa78a34340e9dbc3248095f44d81d0e1c23193 https://git.kernel.org/stable/c/a2e706841488f474c06e9b33f71afc947fb3bf56 https://git.kernel.org/stable/c/db006d7edbf0b4800390ece3727a82f4ae764043 https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-27423.mbox https://bugzilla.redhat.com/show_bug.cgi?id=2281085
https://www.suse.com/security/cve/CVE-2024-27423.html cvss 5.3
joeyli@linux-691t:/mnt/working/source_code-git/kernel-source> ./scripts/check-kernel-fix CVE-2024-27423 a2e706841488 ("netrom: Fix a data-race around sysctl_netrom_transport_requested_window_size") merged v6.8~19^2~2^2~4 Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") merged v2.6.12-rc2^0 Security fix for CVE-2024-27423 bsc#1224762 with CVSS 5.3 Experts candidates: mkubecek@suse.cz denis.kirjanov@suse.com davide.benini@suse.com .............................. ACTION NEEDED! SLE12-SP5: MANUAL: backport a2e706841488f474c06e9b33f71afc947fb3bf56 (Fixes 1da177e4c3f4) SLE15-SP6: MANUAL: backport a2e706841488f474c06e9b33f71afc947fb3bf56 (Fixes 1da177e4c3f4) SLE12-SP3-TD: MANUAL: backport a2e706841488f474c06e9b33f71afc947fb3bf56 (Fixes 1da177e4c3f4) SLE15-SP5: MANUAL: backport a2e706841488f474c06e9b33f71afc947fb3bf56 (Fixes 1da177e4c3f4)
Hi Davide, Because this is a issue for netrom. Could you please help to handle it? If this is not in your area, just reset bug assigner to kernel-bugs@suse.de. Kernel Security Sentinel will find other expert. Thanks a lot!
CVE is now rejected: https://lore.kernel.org/linux-cve-announce/2024052532-REJECTED-e092@gregkh/
(In reply to Andrea Mattiazzo from comment #5) > CVE is now rejected: > https://lore.kernel.org/linux-cve-announce/2024052532-REJECTED-e092@gregkh/ Assigning back to the security team