2024-09-04 20:03:16 +00:00
{
"id" : "CVE-2024-44954" ,
"sourceIdentifier" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"published" : "2024-09-04T19:15:30.353" ,
2024-10-10 20:03:17 +00:00
"lastModified" : "2024-10-10T18:02:42.307" ,
"vulnStatus" : "Analyzed" ,
2024-09-04 20:03:16 +00:00
"cveTags" : [ ] ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: line6: Fix racy access to midibuf\n\nThere can be concurrent accesses to line6 midibuf from both the URB\ncompletion callback and the rawmidi API access. This could be a cause\nof KMSAN warning triggered by syzkaller below (so put as reported-by\nhere).\n\nThis patch protects the midibuf call of the former code path with a\nspinlock for avoiding the possible races."
2024-09-05 14:03:46 +00:00
} ,
{
"lang" : "es" ,
"value" : "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: ALSA: line6: Fix racy access to midibuf Puede haber accesos concurrentes a midibuf de line6 tanto desde la devoluci\u00f3n de llamada de finalizaci\u00f3n de URB como desde el acceso a la API rawmidi. Esto podr\u00eda ser la causa de la advertencia KMSAN activada por syzkaller a continuaci\u00f3n (as\u00ed que se indica aqu\u00ed). Este parche protege la llamada midibuf de la ruta de c\u00f3digo anterior con un spinlock para evitar las posibles ejecuciones."
2024-09-04 20:03:16 +00:00
}
] ,
2024-10-10 20:03:17 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 4.7 ,
"baseSeverity" : "MEDIUM" ,
2024-10-10 20:03:17 +00:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-10-10 20:03:17 +00:00
} ,
"exploitabilityScore" : 1.0 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-362"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.19.320" ,
"matchCriteriaId" : "0B4EF915-550B-45E5-B2CA-648FEACD60FC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartExcluding" : "4.20" ,
"versionEndExcluding" : "5.4.282" ,
"matchCriteriaId" : "21D0A18B-9B7E-4C59-A2A6-8A94BBA4E0FD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.5" ,
"versionEndExcluding" : "5.10.224" ,
"matchCriteriaId" : "5CCEDF13-293D-4E64-B501-4409D0365AFE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartExcluding" : "5.11" ,
"versionEndExcluding" : "5.15.165" ,
"matchCriteriaId" : "87C7E3B8-B82C-459E-AE23-FFE2D952481F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "5.16" ,
"versionEndExcluding" : "6.1.105" ,
"matchCriteriaId" : "89BEB24B-0F37-4C92-A397-564DA7CD8EE9"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.2" ,
"versionEndExcluding" : "6.6.46" ,
"matchCriteriaId" : "FA11941E-81FB-484C-B583-881EEB488340"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "6.7" ,
"versionEndExcluding" : "6.10.5" ,
"matchCriteriaId" : "D074AE50-4A5E-499C-A2FD-75FD60DEA560"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:6.11:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "8B3CE743-2126-47A3-8B7C-822B502CF119"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:linux:linux_kernel:6.11:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "4DEB27E7-30AA-45CC-8934-B89263EF3551"
}
]
}
]
}
] ,
2024-09-04 20:03:16 +00:00
"references" : [
{
"url" : "https://git.kernel.org/stable/c/15b7a03205b31bc5623378c190d22b7ff60026f1" ,
2024-10-10 20:03:17 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-09-04 20:03:16 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/40f3d5cb0e0cbf7fa697913a27d5d361373bdcf5" ,
2024-10-10 20:03:17 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-09-04 20:03:16 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/51d87f11dd199bbc6a85982b088ff27bde53b48a" ,
2024-10-10 20:03:17 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-09-04 20:03:16 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/535df7f896a568a8a1564114eaea49d002cb1747" ,
2024-10-10 20:03:17 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-09-04 20:03:16 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/643293b68fbb6c03f5e907736498da17d43f0d81" ,
2024-10-10 20:03:17 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-09-04 20:03:16 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/a54da4b787dcac60b598da69c9c0072812b8282d" ,
2024-10-10 20:03:17 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-09-04 20:03:16 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/c80f454a805443c274394b1db0d1ebf477abd94e" ,
2024-10-10 20:03:17 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-09-04 20:03:16 +00:00
} ,
{
"url" : "https://git.kernel.org/stable/c/e7e7d2b180d8f297cea6db43ea72402fd33e1a29" ,
2024-10-10 20:03:17 +00:00
"source" : "416baaa9-dc9f-4396-8d5f-8c081fb06d67" ,
"tags" : [
"Patch"
]
2024-09-04 20:03:16 +00:00
}
]
}