漏洞信息详情
Linux kernel 缓冲区错误漏洞
漏洞简介
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。
Linux 存在安全漏洞,该漏洞源于net/bluetooth/hci_event.c 在 hci_extended_inquiry_result_evt(又名 CID-51c19bf3d5cf)中有一个板片越界读取。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,详情请关注厂商主页:
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.1
参考网址
来源:MISC
链接:https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=51c19bf3d5cfaa66571e4b88ba2a6f6295311101
来源:MISC
链接:https://syzkaller.appspot.com/text?tag=ReproC&x=15ca2f46900000
来源:MISC
链接:https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.1
来源:MISC
链接:https://syzkaller.appspot.com/bug?id=4bf11aa05c4ca51ce0df86e500fce486552dc8d2
来源:MISC
链接:https://sites.google.com/view/syzscope/kasan-slab-out-of-bounds-read-in-hci_extended_inquiry_result_evt
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Linux-kernel-out-of-bounds-memory-reading-via-hci-extended-inquiry-result-evt-35646
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2509
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2691
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2368
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2256
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164875/Red-Hat-Security-Advisory-2021-4140-02.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2290
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3905
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2409
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3825
受影响实体
暂无
补丁
- Linux kernel 缓冲区错误漏洞的修复措施<!--2021-6-7-->
还没有评论,来说两句吧...