113 Star 72 Fork 311

src-openEuler/kernel

CVE-2024-56570

已完成
CVE和安全问题 拥有者
创建于  
2024-12-27 23:56

一、漏洞信息
漏洞编号:CVE-2024-56570
漏洞归属组件:kernel
漏洞归属的版本:4.19.140,4.19.194,4.19.90,5.10.0,6.1.19,6.4.0,6.6.0
CVSS V3.0分值:
BaseScore:0.0 None
Vector:CVSS:3.0/
漏洞简述:
In the Linux kernel, the following vulnerability has been resolved:ovl: Filter invalid inodes with missing lookup functionAdd a check to the ovl_dentry_weird() function to prevent theprocessing of directory inodes that lack the lookup function.This is important because such inodes can cause errors in overlayfswhen passed to the lowerstack.
漏洞公开时间:2024-12-27 23:15:15
漏洞创建时间:2024-12-27 23:56:17
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2024-56570

更多参考(点击展开)
参考来源 参考链接 来源链接
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/065bf5dd21639f80e68450de16bda829784dbb8c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/5f86e79c0b2287ffdabe6c1b305a36c4e0f40fe3
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/72014e7745cc8250bb8f27bd78694dfd3f1b5773
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/749eac5a6687ec99116e0691d0d71225254654e3
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/c8b359dddb418c60df1a69beea01d1b3322bfe83
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/f9248e2f73fb4afe08324485e98c815ac084d166
416baaa9-dc9f-4396-8d5f-8c081fb06d67 https://git.kernel.org/stable/c/ff43d008bbf9b27ada434d6455f039a5ef6cee53
suse_bugzilla http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-56570 https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2024/CVE-2024-56570.mbox https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://git.kernel.org/stable/c/f9248e2f73fb4afe08324485e98c815ac084d166 https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://git.kernel.org/stable/c/5f86e79c0b2287ffdabe6c1b305a36c4e0f40fe3 https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://git.kernel.org/stable/c/749eac5a6687ec99116e0691d0d71225254654e3 https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://git.kernel.org/stable/c/ff43d008bbf9b27ada434d6455f039a5ef6cee53 https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://git.kernel.org/stable/c/065bf5dd21639f80e68450de16bda829784dbb8c https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://git.kernel.org/stable/c/72014e7745cc8250bb8f27bd78694dfd3f1b5773 https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://git.kernel.org/stable/c/c8b359dddb418c60df1a69beea01d1b3322bfe83 https://bugzilla.suse.com/show_bug.cgi?id=1235035
suse_bugzilla https://www.cve.org/CVERecord?id=CVE-2024-56570 https://bugzilla.suse.com/show_bug.cgi?id=1235035
debian https://security-tracker.debian.org/tracker/CVE-2024-56570

漏洞分析指导链接:
https://gitee.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/manual.md
漏洞数据来源:
openBrain开源漏洞感知系统
漏洞补丁信息:

详情(点击展开)

二、漏洞分析结构反馈
影响性分析说明:
In the Linux kernel, the following vulnerability has been resolved:ovl: Filter invalid inodes with missing lookup functionAdd a check to the ovl_dentry_weird() function to prevent theprocessing of directory inodes that lack the lookup function.This is important because such inodes can cause errors in overlayfswhen passed to the lowerstack.The Linux kernel CVE team has assigned CVE-2024-56570 to this issue.
openEuler评分:
8.0
Vector:CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
受影响版本排查(受影响/不受影响):
1.openEuler-20.03-LTS-SP4(4.19.90):受影响
2.openEuler-22.03-LTS-SP1(5.10.0):受影响
3.openEuler-22.03-LTS-SP3(5.10.0):受影响
4.openEuler-22.03-LTS-SP4(5.10.0):受影响
5.openEuler-24.03-LTS(6.6.0):受影响
6.openEuler-24.03-LTS-SP1(6.6.0):受影响
7.master:不受影响
8.openEuler-24.03-LTS-Next(6.6.0):不受影响

修复是否涉及abi变化(是/否):
1.openEuler-20.03-LTS-SP4(4.19.90):否
2.openEuler-22.03-LTS-SP1(5.10.0):否
3.openEuler-22.03-LTS-SP3(5.10.0):否
4.master:否
5.openEuler-24.03-LTS(6.6.0):否
6.openEuler-24.03-LTS-Next(6.6.0):否
7.openEuler-22.03-LTS-SP4(5.10.0):否
8.openEuler-24.03-LTS-SP1(6.6.0):否

原因说明:
1.openEuler-20.03-LTS-SP4(4.19.90):正常修复
2.openEuler-22.03-LTS-SP1(5.10.0):正常修复
3.openEuler-22.03-LTS-SP3(5.10.0):正常修复
4.openEuler-22.03-LTS-SP4(5.10.0):正常修复
5.openEuler-24.03-LTS(6.6.0):正常修复
6.openEuler-24.03-LTS-SP1(6.6.0):正常修复
7.master:不受影响-漏洞代码不能被攻击者触发
8.openEuler-24.03-LTS-Next(6.6.0):不受影响-漏洞代码不能被攻击者触发

三、漏洞修复
安全公告链接:https://www.openeuler.org/zh/security/safety-bulletin/detail/?id=openEuler-SA-2025-1079

评论 (10)

登录 后才可以发表评论

状态
负责人
项目
里程碑
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
分支
开始日期   -   截止日期
-
置顶选项
优先级
预计工期 (小时)
参与者(1)
5329419 openeuler ci bot 1632792936
1
https://gitee.com/src-openeuler/kernel.git
git@gitee.com:src-openeuler/kernel.git
src-openeuler
kernel
kernel

搜索帮助