Skip to main content

Threats Tagged 'cve-2024-35895'

View all threats tagged with 'cve-2024-35895'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-35895

Threats Tagged 'cve-2024-35895'

Click on any threat for detailed analysis and mitigation recommendations

0

Red Hat has issued a security advisory for multiple vulnerabilities in the Linux kernel packages included in Red Hat Enterprise Linux 9.2 Extended Update Support and related products. The update addresses 14 distinct security issues ranging from use-after-free bugs, lock inversion deadlocks, malformed packet handling, to potential crashes and undefined behavior. The advisory rates the overall impact as moderate and requires a system reboot after applying the update.

Join the discussion
0

A security advisory from Red Hat addresses multiple vulnerabilities in the kernel-rt packages, which provide the Real Time Linux Kernel for systems requiring high determinism. The update fixes 14 distinct security issues including use-after-free, lock inversion deadlocks, unsafe memory reads, malformed packet handling, and potential crashes. These vulnerabilities affect Red Hat Enterprise Linux 9.2 Extended Update Support versions. The advisory rates the overall impact as moderate and requires a system reboot after applying the update.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Prevent lock inversion deadlock in map delete elem syzkaller started using corpuses where a BPF tracing program deletes elements from a sockmap/sockhash map. Because BPF tracing programs can be invoked from any interrupt context, locks taken during a map_delete_elem operation must be hardirq-safe. Otherwise a deadlock due to lock inversion is possible, as reported by lockdep: CPU0 CPU1 ---- ---- lock(&htab->buckets[i].lock); local_irq_disable(); lock(&host->lock); lock(&htab->buckets[i].lock); <Interrupt> lock(&host->lock); Locks in sockmap are hardirq-unsafe by design. We expects elements to be deleted from sockmap/sockhash only in task (normal) context with interrupts enabled, or in softirq context. Detect when map_delete_elem operation is invoked from a context which is _not_ hardirq-unsafe, that is interrupts are disabled, and bail out with an error. Note that map updates are not affected by this issue. BPF verifier does not allow updating sockmap/sockhash from a BPF tracing program today.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2024-35895
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses