CVE-2024-47093
Jue, 19/12/2024 – 15:15
CVE-2024-47093
CVE-2024-47093
Jue, 19/12/2024 – 15:15
CVE-2024-47093
CVE-2024-25131
Jue, 19/12/2024 – 15:15
CVE-2024-25131
CVE-2024-12787
Jue, 19/12/2024 – 16:15
CVE-2024-12787
CVE-2024-12798
Jue, 19/12/2024 – 16:15
CVE-2024-12798
Malicious logback configuration files can allow the attacker to execute
arbitrary code using the JaninoEventEvaluator extension.
A successful attack requires the user to have write access to a
configuration file. Alternatively, the attacker could inject a malicious
environment variable pointing to a malicious configuration file. In both
cases, the attack requires existing privilege.
CVE-2024-38864
Jue, 19/12/2024 – 16:15
CVE-2024-38864
CVE-2024-9154
Jue, 19/12/2024 – 16:15
CVE-2024-9154
CVE-2024-55082
Jue, 19/12/2024 – 16:15
CVE-2024-55082
CVE-2024-45819
Jue, 19/12/2024 – 12:15
CVE-2024-45819
CVE-2024-45818
Jue, 19/12/2024 – 12:15
CVE-2024-45818
This deadlock was already found when the code was first introduced, but
was analysed incorrectly and the fix was incomplete. Analysis in light
of the new finding cannot find a way to make the existing locking
discipline work.
In staging, this logic has all been removed because it was discovered
to be accidentally disabled since Xen 4.7. Therefore, we are fixing the
locking problem by backporting the removal of most of the feature. Note
that even with the feature disabled, the lock would still be acquired
for any accesses to the VGA MMIO region.
CVE-2024-12782
Jue, 19/12/2024 – 13:15
CVE-2024-12782