U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-47725

Change History

CVE Translated by kernel.org 10/23/2024 2:15:05 AM

Action Type Old Value New Value
Removed Translation
Title: kernel de Linux
Description: En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: dm-verity: reiniciar o entrar en pánico en un error de E/S Maxim Suhanov informó que dm-verity no se bloquea si ocurre un error de E/S. En teoría, esto podría usarse para subvertir la seguridad, porque un atacante puede crear sectores que devuelvan un error con el comando Write Uncorrectable. Algunos programas pueden comportarse mal si tienen que lidiar con EIO. Esta confirmación corrige dm-verity, de modo que si se especificó "panic_on_corruption" o "restart_on_corruption" y ocurre un error de E/S, la máquina entrará en pánico o se reiniciará. Esta confirmación también cambia kernel_restart a emergency_restart - kernel_restart llama a los notificadores de reinicio y estos notificadores de reinicio pueden esperar al bio que falló. emergency_restart no llama a los notificadores.

								
						

CVE Modified by kernel.org 10/23/2024 2:15:05 AM

Action Type Old Value New Value
Changed Description
In the Linux kernel, the following vulnerability has been resolved:

dm-verity: restart or panic on an I/O error

Maxim Suhanov reported that dm-verity doesn't crash if an I/O error
happens. In theory, this could be used to subvert security, because an
attacker can create sectors that return error with the Write Uncorrectable
command. Some programs may misbehave if they have to deal with EIO.

This commit fixes dm-verity, so that if "panic_on_corruption" or
"restart_on_corruption" was specified and an I/O error happens, the
machine will panic or restart.

This commit also changes kernel_restart to emergency_restart -
kernel_restart calls reboot notifiers and these reboot notifiers may wait
for the bio that failed. emergency_restart doesn't call the notifiers.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Removed Reference
kernel.org https://git.kernel.org/stable/c/338b32a232bbee39e52dd1486cbc0c9f458d4d69

								
						
Removed Reference
kernel.org https://git.kernel.org/stable/c/b332bcca59143cfdd000957f8b78c28dd2ac1da4

								
						
Removed Reference
kernel.org https://git.kernel.org/stable/c/cada2646b7483cce370eb3b046659df31d9d34d1

								
						
Removed Reference
kernel.org https://git.kernel.org/stable/c/e6a3531dd542cb127c8de32ab1e54a48ae19962b

								
						

CVE Rejected by kernel.org 10/23/2024 2:15:05 AM

Action Type Old Value New Value