VARIoT IoT vulnerabilities database
| VAR-202406-0045 | CVE-2024-5597 | Fuji Electric's Monitouch V-SFT Vulnerability regarding mix-ups in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Fuji Electric Monitouch V-SFT is vulnerable to a type confusion, which could cause a crash or code execution. Fuji Electric's Monitouch V-SFT contains a type confusion vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of V9 files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Fuji Electric Monitouch V-SFT is a human-machine interface software from Fuji Electric
| VAR-202406-2008 | CVE-2024-36782 | TOTOLINK of CP300 Vulnerability related to use of hardcoded credentials in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root. TOTOLINK of CP300 A vulnerability exists in the firmware regarding the use of hardcoded credentials.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TOTOLINK is a mid-to-high-end wireless router brand in the Asia-Pacific region
| VAR-202406-1058 | CVE-2024-36783 | TOTOLINK of lr350 Command injection vulnerability in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection via the host_time parameter in the NTPSyncWithHost function. TOTOLINK of lr350 Firmware contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TOTOLINK LR350 is a wireless router from China's TOTOLINK Electronics. No detailed vulnerability details are currently available
| VAR-202406-2211 | CVE-2024-36729 | TRENDnet of TEW-827DRU Stack-based buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 6.3 Severity: MEDIUM |
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action wizard_ipv6 with a sufficiently long reboot_type key. TRENDnet of TEW-827DRU A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202406-1252 | CVE-2024-36728 | TRENDnet of TEW-827DRU Stack-based buffer overflow vulnerability in firmware |
CVSS V2: - CVSS V3: 8.1 Severity: HIGH |
TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by POSTing to apply.cgi via the action vlan_setting with a sufficiently long dns1 or dns 2 key
| VAR-202406-2711 | CVE-2023-43555 | Out-of-bounds read vulnerability in multiple Qualcomm products |
CVSS V2: - CVSS V3: 8.2 Severity: HIGH |
Information disclosure in Video while parsing mp2 clip with invalid section length. AQT1000 firmware, fastconnect 6200 firmware, fastconnect 6700 Multiple Qualcomm products, such as firmware, contain an out-of-bounds read vulnerability.Information may be obtained
| VAR-202406-2297 | CVE-2023-43551 | Authentication vulnerabilities in multiple Qualcomm products |
CVSS V2: - CVSS V3: 9.1 Severity: CRITICAL |
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command. 315 5g iot modem firmware, 9205 lte modem firmware, 9206 lte modem Multiple Qualcomm products, such as firmware, contain vulnerabilities related to authentication.Information may be tampered with
| VAR-202406-2081 | CVE-2024-20070 | Vulnerabilities in the use of encryption algorithms in multiple MediaTek products |
CVSS V2: - CVSS V3: 5.1 Severity: MEDIUM |
In modem, there is a possible information disclosure due to using risky cryptographic algorithm during connection establishment negotiation. This could lead to remote information disclosure, when weak encryption algorithm is used, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00942482; Issue ID: MSV-1469. media tech's NR15 , nr16 , NR17 Exists in the use of cryptographic algorithms.Information is obtained and service operation is interrupted (DoS) It may be in a state
| VAR-202406-1703 | CVE-2024-20069 | media tech's NR15 Vulnerability in |
CVSS V2: - CVSS V3: 6.5 Severity: MEDIUM |
In modem, there is a possible selection of less-secure algorithm during the VoWiFi IKE due to a missing DH downgrade check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01286330; Issue ID: MSV-1430. media tech's NR15 Exists in unspecified vulnerabilities.Information may be obtained
| VAR-202406-2694 | CVE-2024-20068 | media tech's nr16 and NR17 Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 5.9 Severity: MEDIUM |
In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is no needed for exploitation. Patch ID: MOLY01270721; Issue ID: MSV-1479. media tech's nr16 and NR17 Exists in an out-of-bounds write vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202406-2276 | CVE-2024-20067 | media tech's nr16 and NR17 Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 9.8 Severity: CRITICAL |
In modem, there is a possible out of bounds write due to improper input invalidation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267285; Issue ID: MSV-1462. media tech's nr16 and NR17 Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202406-1535 | CVE-2024-20066 | media tech's nr16 and NR17 Out-of-bounds write vulnerability in |
CVSS V2: - CVSS V3: 7.5 Severity: HIGH |
In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is no needed for exploitation. Patch ID: MOLY01267281; Issue ID: MSV-1477. media tech's nr16 and NR17 Exists in an out-of-bounds write vulnerability.Service operation interruption (DoS) It may be in a state
| VAR-202406-1374 | No CVE | Raisecom iSDC of Raisecom Technology Development Co., Ltd. has a command execution vulnerability |
CVSS V2: 7.1 CVSS V3: - Severity: HIGH |
Raisecom Technology Development Co., Ltd. is a provider of optical network products and system solutions.
Raisecom iSDC of Raisecom Technology Development Co., Ltd. has a command execution vulnerability, which can be exploited by attackers to obtain server permissions.
| VAR-202405-1938 | CVE-2024-5271 | Fuji Electric's Monitouch V-SFT Vulnerability regarding mix-ups in |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: High |
Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a
type confusion, which could result in arbitrary code execution. Fuji Electric's Monitouch V-SFT contains a type confusion vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of V9C files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Fuji Electric Monitouch V-SFT is a screen configuration software from Fuji Electric of Japan
| VAR-202405-1939 | CVE-2024-34171 | Fuji Electric Monitouch V-SFT V9C File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability |
CVSS V2: 10.0 CVSS V3: 7.8 Severity: HIGH |
Fuji Electric Monitouch V-SFT
is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code. (DoS) It may be in a state. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of V9C files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Fuji Electric Monitouch V-SFT is human-machine interface (HMI) configuration software developed by Fuji Electric Co., Ltd., primarily used in industrial automation. It provides functions such as touchscreen interface design, PDF document viewing, video playback, and alarm messaging
| VAR-202405-3607 | CVE-2024-36959 | Linux of Linux Kernel Vulnerability in |
CVSS V2: 7.2 CVSS V3: 5.5 Severity: MEDIUM |
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map()
If we fail to allocate propname buffer, we need to drop the reference
count we just took. Because the pinctrl_dt_free_maps() includes the
droping operation, here we call it directly. Linux of Linux Kernel Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces.
SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs).
Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server
| VAR-202405-3608 | CVE-2024-36940 | Linux of Linux Kernel Double release vulnerability in products from multiple vendors such as |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: core: delete incorrect free in pinctrl_enable()
The "pctldev" struct is allocated in devm_pinctrl_register_and_init().
It's a devm_ managed pointer that is freed by devm_pinctrl_dev_release(),
so freeing it in pinctrl_enable() will lead to a double free.
The devm_pinctrl_dev_release() function frees the pindescs and destroys
the mutex as well. Linux of Linux Kernel Products from multiple vendors, such as the following, contain vulnerabilities related to double frees.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces.
SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs).
Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server. ==========================================================================
Ubuntu Security Notice USN-6972-1
August 21, 2024
linux, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-gcp-4.15: Linux kernel for Google Cloud Platform (GCP) systems
- linux-kvm: Linux kernel for cloud environments
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-hwe: Linux hardware enablement (HWE) kernel
Details:
Yuxuan Hu discovered that the Bluetooth RFCOMM protocol driver in the Linux
Kernel contained a race condition, leading to a NULL pointer dereference.
An attacker could possibly use this to cause a denial of service (system
crash). (CVE-2024-22099)
It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- SuperH RISC architecture;
- User-Mode Linux (UML);
- GPU drivers;
- MMC subsystem;
- Network drivers;
- PHY drivers;
- Pin controllers subsystem;
- Xen hypervisor drivers;
- GFS2 file system;
- Core kernel;
- Bluetooth subsystem;
- IPv4 networking;
- IPv6 networking;
- HD-audio driver;
- ALSA SH drivers;
(CVE-2024-26903, CVE-2024-35835, CVE-2023-52644, CVE-2024-39292,
CVE-2024-36940, CVE-2024-26600, CVE-2023-52629, CVE-2024-35955,
CVE-2023-52760, CVE-2023-52806, CVE-2024-39484, CVE-2024-26679,
CVE-2024-26654, CVE-2024-36901, CVE-2024-26687, CVE-2023-52470)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS
linux-image-4.15.0-1155-kvm 4.15.0-1155.160
Available with Ubuntu Pro
linux-image-4.15.0-1165-gcp 4.15.0-1165.182
Available with Ubuntu Pro
linux-image-4.15.0-228-generic 4.15.0-228.240
Available with Ubuntu Pro
linux-image-4.15.0-228-lowlatency 4.15.0-228.240
Available with Ubuntu Pro
linux-image-gcp-lts-18.04 4.15.0.1165.178
Available with Ubuntu Pro
linux-image-generic 4.15.0.228.212
Available with Ubuntu Pro
linux-image-kvm 4.15.0.1155.146
Available with Ubuntu Pro
linux-image-lowlatency 4.15.0.228.212
Available with Ubuntu Pro
linux-image-virtual 4.15.0.228.212
Available with Ubuntu Pro
Ubuntu 16.04 LTS
linux-image-4.15.0-1165-gcp 4.15.0-1165.182~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-228-generic 4.15.0-228.240~16.04.1
Available with Ubuntu Pro
linux-image-4.15.0-228-lowlatency 4.15.0-228.240~16.04.1
Available with Ubuntu Pro
linux-image-gcp 4.15.0.1165.182~16.04.1
Available with Ubuntu Pro
linux-image-generic-hwe-16.04 4.15.0.228.240~16.04.1
Available with Ubuntu Pro
linux-image-gke 4.15.0.1165.182~16.04.1
Available with Ubuntu Pro
linux-image-lowlatency-hwe-16.04 4.15.0.228.240~16.04.1
Available with Ubuntu Pro
linux-image-oem 4.15.0.228.240~16.04.1
Available with Ubuntu Pro
linux-image-virtual-hwe-16.04 4.15.0.228.240~16.04.1
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6972-1
CVE-2023-52470, CVE-2023-52629, CVE-2023-52644, CVE-2023-52760,
CVE-2023-52806, CVE-2024-22099, CVE-2024-24860, CVE-2024-26600,
CVE-2024-26654, CVE-2024-26679, CVE-2024-26687, CVE-2024-26903,
CVE-2024-35835, CVE-2024-35955, CVE-2024-36901, CVE-2024-36940,
CVE-2024-39292, CVE-2024-39484
| VAR-202405-2071 | CVE-2024-36929 | Debian In products from multiple vendors such as NULL Pointer dereference vulnerability |
CVSS V2: 7.2 CVSS V3: 5.5 Severity: MEDIUM |
In the Linux kernel, the following vulnerability has been resolved:
net: core: reject skb_copy(_expand) for fraglist GSO skbs
SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become
invalid. Return NULL if such an skb is passed to skb_copy or
skb_copy_expand, in order to prevent a crash on a potential later
call to skb_gso_segment. Information handled by the software will not be rewritten. In addition, the software may stop functioning completely. Furthermore, attacks that exploit this vulnerability will not affect other software. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces.
SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs).
Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server. ==========================================================================
Ubuntu Security Notice USN-6950-1
August 08, 2024
linux, linux-aws, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop,
linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gke: Linux kernel for Google Container Engine (GKE) systems
- linux-gkeop: Linux kernel for Google Container Engine (GKE) systems
- linux-intel-iotg: Linux kernel for Intel IoT platforms
- linux-kvm: Linux kernel for cloud environments
- linux-lowlatency: Linux low latency kernel
- linux-nvidia: Linux kernel for NVIDIA systems
- linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems
- linux-intel-iotg-5.15: Linux kernel for Intel IoT platforms
- linux-lowlatency-hwe-5.15: Linux low latency kernel
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- Block layer subsystem;
- Bluetooth drivers;
- Clock framework and drivers;
- FireWire subsystem;
- GPU drivers;
- InfiniBand drivers;
- Multiple devices driver;
- EEPROM drivers;
- Network drivers;
- Pin controllers subsystem;
- Remote Processor subsystem;
- S/390 drivers;
- SCSI drivers;
- 9P distributed file system;
- Network file system client;
- SMB network file system;
- Socket messages infrastructure;
- Dynamic debug library;
- Bluetooth subsystem;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- NSH protocol;
- Phonet protocol;
- TIPC protocol;
- Wireless networking;
- Key management;
- ALSA framework;
- HD-audio driver;
(CVE-2024-36883, CVE-2024-36940, CVE-2024-36902, CVE-2024-36975,
CVE-2024-36964, CVE-2024-36938, CVE-2024-36931, CVE-2024-35848,
CVE-2024-26900, CVE-2024-36967, CVE-2024-36904, CVE-2024-27398,
CVE-2024-36031, CVE-2023-52585, CVE-2024-36886, CVE-2024-36937,
CVE-2024-36954, CVE-2024-36916, CVE-2024-36905, CVE-2024-36959,
CVE-2024-26980, CVE-2024-26936, CVE-2024-36928, CVE-2024-36889,
CVE-2024-36929, CVE-2024-36933, CVE-2024-27399, CVE-2024-36946,
CVE-2024-36906, CVE-2024-36965, CVE-2024-36957, CVE-2024-36941,
CVE-2024-36897, CVE-2024-36952, CVE-2024-36947, CVE-2024-36950,
CVE-2024-36880, CVE-2024-36017, CVE-2023-52882, CVE-2024-36969,
CVE-2024-38600, CVE-2024-36955, CVE-2024-36960, CVE-2024-27401,
CVE-2024-36919, CVE-2024-36934, CVE-2024-35947, CVE-2024-36953,
CVE-2024-36944, CVE-2024-36939)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
linux-image-5.15.0-1050-gkeop 5.15.0-1050.57
linux-image-5.15.0-1062-intel-iotg 5.15.0-1062.68
linux-image-5.15.0-1062-nvidia 5.15.0-1062.63
linux-image-5.15.0-1062-nvidia-lowlatency 5.15.0-1062.63
linux-image-5.15.0-1064-gke 5.15.0-1064.70
linux-image-5.15.0-1064-kvm 5.15.0-1064.69
linux-image-5.15.0-1066-gcp 5.15.0-1066.74
linux-image-5.15.0-1067-aws 5.15.0-1067.73
linux-image-5.15.0-118-generic 5.15.0-118.128
linux-image-5.15.0-118-generic-64k 5.15.0-118.128
linux-image-5.15.0-118-generic-lpae 5.15.0-118.128
linux-image-5.15.0-118-lowlatency 5.15.0-118.128
linux-image-5.15.0-118-lowlatency-64k 5.15.0-118.128
linux-image-aws-lts-22.04 5.15.0.1067.67
linux-image-gcp-lts-22.04 5.15.0.1066.62
linux-image-generic 5.15.0.118.118
linux-image-generic-64k 5.15.0.118.118
linux-image-generic-lpae 5.15.0.118.118
linux-image-gke 5.15.0.1064.63
linux-image-gke-5.15 5.15.0.1064.63
linux-image-gkeop 5.15.0.1050.49
linux-image-gkeop-5.15 5.15.0.1050.49
linux-image-intel-iotg 5.15.0.1062.62
linux-image-kvm 5.15.0.1064.60
linux-image-lowlatency 5.15.0.118.108
linux-image-lowlatency-64k 5.15.0.118.108
linux-image-nvidia 5.15.0.1062.62
linux-image-nvidia-lowlatency 5.15.0.1062.62
linux-image-virtual 5.15.0.118.118
Ubuntu 20.04 LTS
linux-image-5.15.0-1062-intel-iotg 5.15.0-1062.68~20.04.1
linux-image-5.15.0-1066-gcp 5.15.0-1066.74~20.04.1
linux-image-5.15.0-118-lowlatency 5.15.0-118.128~20.04.1
linux-image-5.15.0-118-lowlatency-64k 5.15.0-118.128~20.04.1
linux-image-gcp 5.15.0.1066.74~20.04.1
linux-image-intel 5.15.0.1062.68~20.04.1
linux-image-intel-iotg 5.15.0.1062.68~20.04.1
linux-image-lowlatency-64k-hwe-20.04 5.15.0.118.128~20.04.1
linux-image-lowlatency-hwe-20.04 5.15.0.118.128~20.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6950-1
CVE-2023-52585, CVE-2023-52882, CVE-2024-26900, CVE-2024-26936,
CVE-2024-26980, CVE-2024-27398, CVE-2024-27399, CVE-2024-27401,
CVE-2024-35848, CVE-2024-35947, CVE-2024-36017, CVE-2024-36031,
CVE-2024-36880, CVE-2024-36883, CVE-2024-36886, CVE-2024-36889,
CVE-2024-36897, CVE-2024-36902, CVE-2024-36904, CVE-2024-36905,
CVE-2024-36906, CVE-2024-36916, CVE-2024-36919, CVE-2024-36928,
CVE-2024-36929, CVE-2024-36931, CVE-2024-36933, CVE-2024-36934,
CVE-2024-36937, CVE-2024-36938, CVE-2024-36939, CVE-2024-36940,
CVE-2024-36941, CVE-2024-36944, CVE-2024-36946, CVE-2024-36947,
CVE-2024-36950, CVE-2024-36952, CVE-2024-36953, CVE-2024-36954,
CVE-2024-36955, CVE-2024-36957, CVE-2024-36959, CVE-2024-36960,
CVE-2024-36964, CVE-2024-36965, CVE-2024-36967, CVE-2024-36969,
CVE-2024-36975, CVE-2024-38600
Package Information:
https://launchpad.net/ubuntu/+source/linux/5.15.0-118.128
https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1067.73
https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1066.74
https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1064.70
https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1050.57
https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1062.68
https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1064.69
https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-118.128
https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1062.63
https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1066.74~20.04.1
https://launchpad.net/ubuntu/+source/linux-intel-iotg-5.15/5.15.0-1062.68~20.04.1
https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-118.128~20.04.1
| VAR-202405-3054 | CVE-2024-36916 | Debian Out-of-bounds read vulnerabilities in products from multiple vendors, including |
CVSS V2: 7.2 CVSS V3: 7.1 Severity: HIGH |
In the Linux kernel, the following vulnerability has been resolved:
blk-iocost: avoid out of bounds shift
UBSAN catches undefined behavior in blk-iocost, where sometimes
iocg->delay is shifted right by a number that is too large,
resulting in undefined behavior on some architectures.
[ 186.556576] ------------[ cut here ]------------
UBSAN: shift-out-of-bounds in block/blk-iocost.c:1366:23
shift exponent 64 is too large for 64-bit type 'u64' (aka 'unsigned long long')
CPU: 16 PID: 0 Comm: swapper/16 Tainted: G S E N 6.9.0-0_fbk700_debug_rc2_kbuilder_0_gc85af715cac0 #1
Hardware name: Quanta Twin Lakes MP/Twin Lakes Passive MP, BIOS F09_3A23 12/08/2020
Call Trace:
<IRQ>
dump_stack_lvl+0x8f/0xe0
__ubsan_handle_shift_out_of_bounds+0x22c/0x280
iocg_kick_delay+0x30b/0x310
ioc_timer_fn+0x2fb/0x1f80
__run_timer_base+0x1b6/0x250
...
Avoid that undefined behavior by simply taking the
"delay = 0" branch if the shift is too large.
I am not sure what the symptoms of an undefined value
delay will be, but I suspect it could be more than a
little annoying to debug. [ 186.556576] ------------[ cut here ]------------ UBSAN: block/blk-iocost.c:1366:23 Out of shift range. shift index 64 teeth 64 Bit type 'u64'( alias 'unsigned long long') It's too big for that. delay The exact symptoms this causes are unknown, but we believe it can cause some pretty nasty debugging issues.All information handled by the software may be leaked to the outside. Furthermore, information handled by the software will not be rewritten. Furthermore, the software may stop functioning completely. Furthermore, attacks exploiting this vulnerability will not affect other software. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces.
SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs).
Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server. ==========================================================================
Ubuntu Security Notice USN-6950-1
August 08, 2024
linux, linux-aws, linux-gcp, linux-gcp-5.15, linux-gke, linux-gkeop,
linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency,
linux-lowlatency-hwe-5.15, linux-nvidia vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gke: Linux kernel for Google Container Engine (GKE) systems
- linux-gkeop: Linux kernel for Google Container Engine (GKE) systems
- linux-intel-iotg: Linux kernel for Intel IoT platforms
- linux-kvm: Linux kernel for cloud environments
- linux-lowlatency: Linux low latency kernel
- linux-nvidia: Linux kernel for NVIDIA systems
- linux-gcp-5.15: Linux kernel for Google Cloud Platform (GCP) systems
- linux-intel-iotg-5.15: Linux kernel for Intel IoT platforms
- linux-lowlatency-hwe-5.15: Linux low latency kernel
Details:
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM32 architecture;
- ARM64 architecture;
- Block layer subsystem;
- Bluetooth drivers;
- Clock framework and drivers;
- FireWire subsystem;
- GPU drivers;
- InfiniBand drivers;
- Multiple devices driver;
- EEPROM drivers;
- Network drivers;
- Pin controllers subsystem;
- Remote Processor subsystem;
- S/390 drivers;
- SCSI drivers;
- 9P distributed file system;
- Network file system client;
- SMB network file system;
- Socket messages infrastructure;
- Dynamic debug library;
- Bluetooth subsystem;
- Networking core;
- IPv4 networking;
- IPv6 networking;
- Multipath TCP;
- NSH protocol;
- Phonet protocol;
- TIPC protocol;
- Wireless networking;
- Key management;
- ALSA framework;
- HD-audio driver;
(CVE-2024-36883, CVE-2024-36940, CVE-2024-36902, CVE-2024-36975,
CVE-2024-36964, CVE-2024-36938, CVE-2024-36931, CVE-2024-35848,
CVE-2024-26900, CVE-2024-36967, CVE-2024-36904, CVE-2024-27398,
CVE-2024-36031, CVE-2023-52585, CVE-2024-36886, CVE-2024-36937,
CVE-2024-36954, CVE-2024-36916, CVE-2024-36905, CVE-2024-36959,
CVE-2024-26980, CVE-2024-26936, CVE-2024-36928, CVE-2024-36889,
CVE-2024-36929, CVE-2024-36933, CVE-2024-27399, CVE-2024-36946,
CVE-2024-36906, CVE-2024-36965, CVE-2024-36957, CVE-2024-36941,
CVE-2024-36897, CVE-2024-36952, CVE-2024-36947, CVE-2024-36950,
CVE-2024-36880, CVE-2024-36017, CVE-2023-52882, CVE-2024-36969,
CVE-2024-38600, CVE-2024-36955, CVE-2024-36960, CVE-2024-27401,
CVE-2024-36919, CVE-2024-36934, CVE-2024-35947, CVE-2024-36953,
CVE-2024-36944, CVE-2024-36939)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
linux-image-5.15.0-1050-gkeop 5.15.0-1050.57
linux-image-5.15.0-1062-intel-iotg 5.15.0-1062.68
linux-image-5.15.0-1062-nvidia 5.15.0-1062.63
linux-image-5.15.0-1062-nvidia-lowlatency 5.15.0-1062.63
linux-image-5.15.0-1064-gke 5.15.0-1064.70
linux-image-5.15.0-1064-kvm 5.15.0-1064.69
linux-image-5.15.0-1066-gcp 5.15.0-1066.74
linux-image-5.15.0-1067-aws 5.15.0-1067.73
linux-image-5.15.0-118-generic 5.15.0-118.128
linux-image-5.15.0-118-generic-64k 5.15.0-118.128
linux-image-5.15.0-118-generic-lpae 5.15.0-118.128
linux-image-5.15.0-118-lowlatency 5.15.0-118.128
linux-image-5.15.0-118-lowlatency-64k 5.15.0-118.128
linux-image-aws-lts-22.04 5.15.0.1067.67
linux-image-gcp-lts-22.04 5.15.0.1066.62
linux-image-generic 5.15.0.118.118
linux-image-generic-64k 5.15.0.118.118
linux-image-generic-lpae 5.15.0.118.118
linux-image-gke 5.15.0.1064.63
linux-image-gke-5.15 5.15.0.1064.63
linux-image-gkeop 5.15.0.1050.49
linux-image-gkeop-5.15 5.15.0.1050.49
linux-image-intel-iotg 5.15.0.1062.62
linux-image-kvm 5.15.0.1064.60
linux-image-lowlatency 5.15.0.118.108
linux-image-lowlatency-64k 5.15.0.118.108
linux-image-nvidia 5.15.0.1062.62
linux-image-nvidia-lowlatency 5.15.0.1062.62
linux-image-virtual 5.15.0.118.118
Ubuntu 20.04 LTS
linux-image-5.15.0-1062-intel-iotg 5.15.0-1062.68~20.04.1
linux-image-5.15.0-1066-gcp 5.15.0-1066.74~20.04.1
linux-image-5.15.0-118-lowlatency 5.15.0-118.128~20.04.1
linux-image-5.15.0-118-lowlatency-64k 5.15.0-118.128~20.04.1
linux-image-gcp 5.15.0.1066.74~20.04.1
linux-image-intel 5.15.0.1062.68~20.04.1
linux-image-intel-iotg 5.15.0.1062.68~20.04.1
linux-image-lowlatency-64k-hwe-20.04 5.15.0.118.128~20.04.1
linux-image-lowlatency-hwe-20.04 5.15.0.118.128~20.04.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6950-1
CVE-2023-52585, CVE-2023-52882, CVE-2024-26900, CVE-2024-26936,
CVE-2024-26980, CVE-2024-27398, CVE-2024-27399, CVE-2024-27401,
CVE-2024-35848, CVE-2024-35947, CVE-2024-36017, CVE-2024-36031,
CVE-2024-36880, CVE-2024-36883, CVE-2024-36886, CVE-2024-36889,
CVE-2024-36897, CVE-2024-36902, CVE-2024-36904, CVE-2024-36905,
CVE-2024-36906, CVE-2024-36916, CVE-2024-36919, CVE-2024-36928,
CVE-2024-36929, CVE-2024-36931, CVE-2024-36933, CVE-2024-36934,
CVE-2024-36937, CVE-2024-36938, CVE-2024-36939, CVE-2024-36940,
CVE-2024-36941, CVE-2024-36944, CVE-2024-36946, CVE-2024-36947,
CVE-2024-36950, CVE-2024-36952, CVE-2024-36953, CVE-2024-36954,
CVE-2024-36955, CVE-2024-36957, CVE-2024-36959, CVE-2024-36960,
CVE-2024-36964, CVE-2024-36965, CVE-2024-36967, CVE-2024-36969,
CVE-2024-36975, CVE-2024-38600
Package Information:
https://launchpad.net/ubuntu/+source/linux/5.15.0-118.128
https://launchpad.net/ubuntu/+source/linux-aws/5.15.0-1067.73
https://launchpad.net/ubuntu/+source/linux-gcp/5.15.0-1066.74
https://launchpad.net/ubuntu/+source/linux-gke/5.15.0-1064.70
https://launchpad.net/ubuntu/+source/linux-gkeop/5.15.0-1050.57
https://launchpad.net/ubuntu/+source/linux-intel-iotg/5.15.0-1062.68
https://launchpad.net/ubuntu/+source/linux-kvm/5.15.0-1064.69
https://launchpad.net/ubuntu/+source/linux-lowlatency/5.15.0-118.128
https://launchpad.net/ubuntu/+source/linux-nvidia/5.15.0-1062.63
https://launchpad.net/ubuntu/+source/linux-gcp-5.15/5.15.0-1066.74~20.04.1
https://launchpad.net/ubuntu/+source/linux-intel-iotg-5.15/5.15.0-1062.68~20.04.1
https://launchpad.net/ubuntu/+source/linux-lowlatency-hwe-5.15/5.15.0-118.128~20.04.1
| VAR-202405-2862 | CVE-2024-36905 | Debian Vulnerabilities related to division by zero in products from multiple vendors, such as |
CVSS V2: 7.2 CVSS V3: 5.5 Severity: MEDIUM |
In the Linux kernel, the following vulnerability has been resolved:
tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets
TCP_SYN_RECV state is really special, it is only used by
cross-syn connections, mostly used by fuzzers.
In the following crash [1], syzbot managed to trigger a divide
by zero in tcp_rcv_space_adjust()
A socket makes the following state transitions,
without ever calling tcp_init_transfer(),
meaning tcp_init_buffer_space() is also not called.
TCP_CLOSE
connect()
TCP_SYN_SENT
TCP_SYN_RECV
shutdown() -> tcp_shutdown(sk, SEND_SHUTDOWN)
TCP_FIN_WAIT1
To fix this issue, change tcp_shutdown() to not
perform a TCP_SYN_RECV -> TCP_FIN_WAIT1 transition,
which makes no sense anyway.
When tcp_rcv_state_process() later changes socket state
from TCP_SYN_RECV to TCP_ESTABLISH, then look at
sk->sk_shutdown to finally enter TCP_FIN_WAIT1 state,
and send a FIN packet from a sane socket state.
This means tcp_send_fin() can now be called from BH
context, and must use GFP_ATOMIC allocations.
[1]
divide error: 0000 [#1] PREEMPT SMP KASAN NOPTI
CPU: 1 PID: 5084 Comm: syz-executor358 Not tainted 6.9.0-rc6-syzkaller-00022-g98369dccd2f8 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024
RIP: 0010:tcp_rcv_space_adjust+0x2df/0x890 net/ipv4/tcp_input.c:767
Code: e3 04 4c 01 eb 48 8b 44 24 38 0f b6 04 10 84 c0 49 89 d5 0f 85 a5 03 00 00 41 8b 8e c8 09 00 00 89 e8 29 c8 48 0f af c3 31 d2 <48> f7 f1 48 8d 1c 43 49 8d 96 76 08 00 00 48 89 d0 48 c1 e8 03 48
RSP: 0018:ffffc900031ef3f0 EFLAGS: 00010246
RAX: 0c677a10441f8f42 RBX: 000000004fb95e7e RCX: 0000000000000000
RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000
RBP: 0000000027d4b11f R08: ffffffff89e535a4 R09: 1ffffffff25e6ab7
R10: dffffc0000000000 R11: ffffffff8135e920 R12: ffff88802a9f8d30
R13: dffffc0000000000 R14: ffff88802a9f8d00 R15: 1ffff1100553f2da
FS: 00005555775c0380(0000) GS:ffff8880b9500000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f1155bf2304 CR3: 000000002b9f2000 CR4: 0000000000350ef0
Call Trace:
<TASK>
tcp_recvmsg_locked+0x106d/0x25a0 net/ipv4/tcp.c:2513
tcp_recvmsg+0x25d/0x920 net/ipv4/tcp.c:2578
inet6_recvmsg+0x16a/0x730 net/ipv6/af_inet6.c:680
sock_recvmsg_nosec net/socket.c:1046 [inline]
sock_recvmsg+0x109/0x280 net/socket.c:1068
____sys_recvmsg+0x1db/0x470 net/socket.c:2803
___sys_recvmsg net/socket.c:2845 [inline]
do_recvmmsg+0x474/0xae0 net/socket.c:2939
__sys_recvmmsg net/socket.c:3018 [inline]
__do_sys_recvmmsg net/socket.c:3041 [inline]
__se_sys_recvmmsg net/socket.c:3034 [inline]
__x64_sys_recvmmsg+0x199/0x250 net/socket.c:3034
do_syscall_x64 arch/x86/entry/common.c:52 [inline]
do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7faeb6363db9
Code: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007ffcc1997168 EFLAGS: 00000246 ORIG_RAX: 000000000000012b
RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007faeb6363db9
RDX: 0000000000000001 RSI: 0000000020000bc0 RDI: 0000000000000005
RBP: 0000000000000000 R08: 0000000000000000 R09: 000000000000001c
R10: 0000000000000122 R11: 0000000000000246 R12: 0000000000000000
R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000001. TCP_SYN_RECV Incorrect shutdown processing for a socket in the SEND_SHUTDOWN ) is delayed, causing the socket in this state to transition without being properly initialized, ultimately resulting in a division-by-zero crash. tcp_shutdown() The function TCP_SYN_RECV from TCP_FIN_WAIT1 This fix corrects the socket state management and prevents an attacker from causing a denial of service ( DoS ) reduces the risk of attack.Information handled by the software will not be leaked to the outside. Information handled by the software will not be rewritten. In addition, the software may stop functioning completely. Furthermore, attacks that exploit this vulnerability will not affect other software. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces.
SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs).
Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server