-

CVE-2024-35815

In the Linux kernel, the following vulnerability has been resolved:

fs/aio: Check IOCB_AIO_RW before the struct aio_kiocb conversion

The first kiocb_set_cancel_fn() argument may point at a struct kiocb
that is not embedded inside struct aio_kiocb. With the current code,
depending on the compiler, the req->ki_ctx read happens either before
the IOCB_AIO_RW test or after that test. Move the req->ki_ctx read such
that it is guaranteed that the IOCB_AIO_RW test happens first.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < 10ca82aff58434e122c7c757cf0497c335f993f3
Version 337b543e274fe7a8f47df3c8293cc6686ffa620f
Status affected
Version < 396dbbc18963648e9d1a4edbb55cfe08fa374d50
Version b4eea7a05ee0ab5ab0514421e6ba8c5d249cf942
Status affected
Version < 94eb0293703ced580f05dfbe5a57da5931e9aee2
Version ea1cd64d59f22d6d13f367d62ec6e27b9344695f
Status affected
Version < a71cba07783abc76b547568b6452cd1dd9981410
Version d7b6fa97ec894edd02f64b83e5e72e1aa352f353
Status affected
Version < 18d5fc3c16cc317bd0e5f5dabe0660df415cadb7
Version 18f614369def2a11a52f569fe0f910b199d13487
Status affected
Version < c01ed748847fe8b810d86efc229b9e6c7fafa01e
Version e7e23fc5d5fe422827c9a43ecb579448f73876c7
Status affected
Version < 5c43d0041e3a05c6c41c318b759fff16d2384596
Version 1dc7d74fe456944a9b1c57bd776280249f441ac6
Status affected
Version < 961ebd120565cb60cebe21cb634fbc456022db4a
Version b820de741ae48ccf50dd95e297889c286ff4f760
Status affected
VendorLinux
Product Linux
Default Statusunaffected
Version < 4.19.312
Version 4.19.308
Status affected
Version < 5.4.274
Version 5.4.270
Status affected
Version < 5.10.215
Version 5.10.211
Status affected
Version < 5.15.154
Version 5.15.150
Status affected
Version < 6.1.84
Version 6.1.80
Status affected
Version < 6.6.24
Version 6.6.19
Status affected
Version < 6.7.12
Version 6.7.7
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.097
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string