ARM:9064/1:hw_breakpoint:不要直接检查事件的overflow_handler挂钩(CVE-2021-47006)

admin 2024-03-01 10:39:45 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
ARM:9064/1:hw_breakpoint:不要直接检查事件的overflow_handler挂钩(CVE-2021-47006)

CVE编号

CVE-2021-47006

利用情况

暂无

补丁情况

N/A

披露时间

2024-02-28
漏洞描述
In the Linux kernel, the following vulnerability has been resolved: ARM: 9064/1: hw_breakpoint: Do not directly check the event's overflow_handler hook The commit 1879445dfa7b ("perf/core: Set event's default ::overflow_handler()") set a default event->overflow_handler in perf_event_alloc(), and replace the check event->overflow_handler with is_default_overflow_handler(), but one is missing. Currently, the bp->overflow_handler can not be NULL. As a result, enable_single_step() is always not invoked. Comments from Zhen Lei: https://patchwork.kernel.org/project/linux-arm-kernel/patch/[email protected]/
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://git.kernel.org/stable/c/3ed8832aeaa9a37b0fc386bb72ff604352567c80
https://git.kernel.org/stable/c/555a70f7fff03bd669123487905c47ae27dbdaac
https://git.kernel.org/stable/c/630146203108bf6b8934eec0dfdb3e46dcb917de
https://git.kernel.org/stable/c/7eeacc6728c5478e3c01bc82a1f08958eaa12366
https://git.kernel.org/stable/c/a506bd5756290821a4314f502b4bafc2afcf5260
https://git.kernel.org/stable/c/a9938d6d78a238d6ab8de57a4d3dcf77adceb9bb
https://git.kernel.org/stable/c/dabe299425b1a53a69461fed7ac8922ea6733a25
https://git.kernel.org/stable/c/ed1f67465327cec4457bb988775245b199da86e6
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
系统 debian_10 linux * Up to (excluding) 4.19.194-1
运行在以下环境
系统 debian_11 linux * Up to (excluding) 5.10.38-1
运行在以下环境
系统 debian_12 linux * Up to (excluding) 5.10.38-1
CVSS3评分 N/A
  • 攻击路径 N/A
  • 攻击复杂度 N/A
  • 权限要求 N/A
  • 影响范围 N/A
  • 用户交互 N/A
  • 可用性 N/A
  • 保密性 N/A
  • 完整性 N/A
N/A
CWE-ID 漏洞类型
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0