漏洞信息详情
Linux kernel 资源管理错误漏洞
漏洞简介
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。
Linux kernel 5.6.8之前版本中的drivers/usb/core/message.c文件的usb_sg_cancel存在资源管理错误漏洞。该漏洞源于网络系统或产品对系统资源(如内存、磁盘空间、文件等)的管理不当。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=056ad39ee9253873522f6469c3364964a322912b
参考网址
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html
来源:MISC
链接:https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=056ad39ee9253873522f6469c3364964a322912b
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20200608-0001/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html
来源:UBUNTU
链接:https://usn.ubuntu.com/4391-1/
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/06/msg00012.html
来源:UBUNTU
链接:https://usn.ubuntu.com/4389-1/
来源:UBUNTU
链接:https://usn.ubuntu.com/4390-1/
来源:UBUNTU
链接:https://usn.ubuntu.com/4387-1/
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html
来源:UBUNTU
链接:https://usn.ubuntu.com/4388-1/
来源:MISC
链接:https://patchwork.kernel.org/patch/11463781/
来源:MISC
链接:https://lkml.org/lkml/2020/3/23/52
来源:MISC
链接:https://github.com/torvalds/linux/commit/056ad39ee9253873522f6469c3364964a322912b
来源:MISC
链接:https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.8
来源:DEBIAN
链接:https://www.debian.org/security/2020/dsa-4698
来源:DEBIAN
链接:https://www.debian.org/security/2020/dsa-4699
来源:source.android.com
链接:https://source.android.com/security/bulletin/2020-08-01
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/158014/Ubuntu-Security-Notice-USN-4388-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1866
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1688
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1732
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1820
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2661/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2009/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3063/
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-flex-system-switch-firmware-products-are-affected-by-a-vulnerability-in-the-kernel-cve-2020-12464/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162837/Red-Hat-Security-Advisory-2021-2136-01.html
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Linux-kernel-use-after-free-via-usb-sg-cancel-32156
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2039/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162626/Red-Hat-Security-Advisory-2021-1578-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/162877/Red-Hat-Security-Advisory-2021-2121-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2739/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2020-12464
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-vulnerabilities-in-linux-kernel-affect-ibm-spectrum-protect-plus/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.3043/
来源:www.nsfocus.net
链接:http://www.nsfocus.net/vulndb/48981
受影响实体
暂无
补丁
- Linux kernel 资源管理错误漏洞的修复措施<!--2020-4-29-->
还没有评论,来说两句吧...