漏洞信息详情
Linux kernel 安全漏洞
漏洞简介
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。
Linux kernel 5.10到5.14.6版本存在安全漏洞,该漏洞源于内核中中 fs/io_uring.c 中的 loop_rw_iter 允许本地用户通过使用 IORING_OP_PROVIDE_BUFFERS 来触发内核缓冲区的释放来获得权限。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=16c8d2df7ec0eed31b7d3b61cb13206a7fb930cc
参考网址
来源:MISC
链接:https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=16c8d2df7ec0eed31b7d3b61cb13206a7fb930cc
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/PAP4TXEZ7J4EZQMQW5SIJMWXG7WZT3F7/
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4978
来源:MISC
链接:http://www.openwall.com/lists/oss-security/2021/09/18/2
来源:CONFIRM
链接:https://security.netapp.com/advisory/ntap-20211014-0003/
来源:FEDORA
链接:https://lists.fedoraproject.org/archives/list/[email protected]/message/J7KSMIOQ4377CVTHMWNGNCWHMCRFRP2T/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164334/Ubuntu-Security-Notice-USN-5092-2.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164312/Ubuntu-Security-Notice-USN-5092-1.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164551/Ubuntu-Security-Notice-USN-5092-3.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3225
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3324
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164431/Ubuntu-Security-Notice-USN-5106-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3249
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/Linux-kernel-reuse-after-free-via-io-uring-loop-rw-iter-36453
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2021-41073
受影响实体
暂无
补丁
- Linux kernel 安全漏洞的修复措施<!--2021-9-19-->
还没有评论,来说两句吧...