Upstream information

CVE-2024-27308 at MITRE

Description

Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid tokens that correspond to named pipes that have already been deregistered from the mio registry. The impact of this vulnerability depends on how mio is used. For some applications, invalid tokens may be ignored or cause a warning or a crash. On the other hand, for applications that store pointers in the tokens, this vulnerability may result in a use-after-free. For users of Tokio, this vulnerability is serious and can result in a use-after-free in Tokio. The vulnerability is Windows-specific, and can only happen if you are using named pipes. Other IO resources are not affected. This vulnerability has been fixed in mio v0.8.11. All versions of mio between v0.7.2 and v0.8.10 are vulnerable. Tokio is vulnerable when you are using a vulnerable version of mio AND you are using at least Tokio v1.30.0. Versions of Tokio prior to v1.30.0 will ignore invalid tokens, so they are not vulnerable. Vulnerable libraries that use mio can work around this issue by detecting and ignoring invalid tokens.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having low severity.

SUSE Bugzilla entry: 1223251 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.


Status of this issue by product and package

Please note that this evaluation state might be work in progress, incomplete or outdated. Also information for service packs in the LTSS phase is only included for issues meeting the LTSS criteria. If in doubt, feel free to contact us for clarification. The updates are grouped by state of their lifecycle. SUSE product lifecycles are documented on the lifecycle page.

Product(s) Source package State
Products under general support and receiving all security fixes.
SUSE Enterprise Storage 7.1 aardvark-dns Not affected
SUSE Enterprise Storage 7.1 netavark Not affected
SUSE Enterprise Storage 7.1 rustup Not affected
SUSE Enterprise Storage 7.1 s390-tools Not affected
SUSE Enterprise Storage 7.1 sccache Not affected
SUSE Linux Enterprise Desktop 15 SP5 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Desktop 15 SP5 rustup Not affected
SUSE Linux Enterprise Desktop 15 SP5 s390-tools Not affected
SUSE Linux Enterprise Desktop 15 SP5 sccache Not affected
SUSE Linux Enterprise Desktop 15 SP6 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Desktop 15 SP6 rustup Not affected
SUSE Linux Enterprise Desktop 15 SP6 s390-tools Not affected
SUSE Linux Enterprise Desktop 15 SP6 sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 aardvark-dns Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 netavark Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 rustup Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 s390-tools Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP5 sevctl Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 aardvark-dns Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 netavark Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 rustup Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 s390-tools Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 sevctl Not affected
SUSE Linux Enterprise High Performance Computing 15 SP6 snpguest Not affected
SUSE Linux Enterprise Micro 5.1 aardvark-dns Not affected
SUSE Linux Enterprise Micro 5.1 netavark Not affected
SUSE Linux Enterprise Micro 5.1 s390-tools Not affected
SUSE Linux Enterprise Micro 5.2 aardvark-dns Not affected
SUSE Linux Enterprise Micro 5.2 afterburn Not affected
SUSE Linux Enterprise Micro 5.2 netavark Not affected
SUSE Linux Enterprise Micro 5.2 s390-tools Not affected
SUSE Linux Enterprise Micro 5.3 aardvark-dns Not affected
SUSE Linux Enterprise Micro 5.3 afterburn Not affected
SUSE Linux Enterprise Micro 5.3 netavark Not affected
SUSE Linux Enterprise Micro 5.3 rust-keylime Not affected
SUSE Linux Enterprise Micro 5.3 s390-tools Not affected
SUSE Linux Enterprise Micro 5.4 aardvark-dns Not affected
SUSE Linux Enterprise Micro 5.4 afterburn Not affected
SUSE Linux Enterprise Micro 5.4 netavark Not affected
SUSE Linux Enterprise Micro 5.4 rust-keylime Not affected
SUSE Linux Enterprise Micro 5.4 s390-tools Not affected
SUSE Linux Enterprise Micro 5.5 aardvark-dns Not affected
SUSE Linux Enterprise Micro 5.5 afterburn Not affected
SUSE Linux Enterprise Micro 5.5 netavark Not affected
SUSE Linux Enterprise Micro 5.5 rust-keylime Not affected
SUSE Linux Enterprise Micro 5.5 s390-tools Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP5 s390-tools Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP6 s390-tools Not affected
SUSE Linux Enterprise Module for Containers 15 SP5 aardvark-dns Not affected
SUSE Linux Enterprise Module for Containers 15 SP5 netavark Not affected
SUSE Linux Enterprise Module for Containers 15 SP6 aardvark-dns Not affected
SUSE Linux Enterprise Module for Containers 15 SP6 netavark Not affected
SUSE Linux Enterprise Module for Desktop Applications 15 SP5 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Module for Desktop Applications 15 SP6 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Module for Development Tools 15 SP5 rustup Not affected
SUSE Linux Enterprise Module for Development Tools 15 SP5 sccache Not affected
SUSE Linux Enterprise Module for Development Tools 15 SP6 rustup Not affected
SUSE Linux Enterprise Module for Development Tools 15 SP6 sccache Not affected
SUSE Linux Enterprise Module for Public Cloud 15 SP5 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Module for Public Cloud 15 SP6 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Module for Server Applications 15 SP5 sevctl Not affected
SUSE Linux Enterprise Module for Server Applications 15 SP6 sevctl Not affected
SUSE Linux Enterprise Module for Server Applications 15 SP6 snpguest Not affected
SUSE Linux Enterprise Server 12 SP5 s390-tools Not affected
SUSE Linux Enterprise Server 15 SP5 aardvark-dns Not affected
SUSE Linux Enterprise Server 15 SP5 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Server 15 SP5 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Server 15 SP5 netavark Not affected
SUSE Linux Enterprise Server 15 SP5 rustup Not affected
SUSE Linux Enterprise Server 15 SP5 s390-tools Not affected
SUSE Linux Enterprise Server 15 SP5 sccache Not affected
SUSE Linux Enterprise Server 15 SP5 sevctl Not affected
SUSE Linux Enterprise Server 15 SP6 aardvark-dns Not affected
SUSE Linux Enterprise Server 15 SP6 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Server 15 SP6 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Server 15 SP6 netavark Not affected
SUSE Linux Enterprise Server 15 SP6 rustup Not affected
SUSE Linux Enterprise Server 15 SP6 s390-tools Not affected
SUSE Linux Enterprise Server 15 SP6 sccache Not affected
SUSE Linux Enterprise Server 15 SP6 sevctl Not affected
SUSE Linux Enterprise Server 15 SP6 snpguest Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 aardvark-dns Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 netavark Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 rustup Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 s390-tools Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 sccache Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP5 sevctl Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 aardvark-dns Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 netavark Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 rustup Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 s390-tools Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 sccache Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 sevctl Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP6 snpguest Not affected
SUSE Manager Proxy 4.3 aardvark-dns Not affected
SUSE Manager Proxy 4.3 aws-nitro-enclaves-cli Not affected
SUSE Manager Proxy 4.3 gstreamer-plugins-rs Not affected
SUSE Manager Proxy 4.3 netavark Not affected
SUSE Manager Proxy 4.3 rustup Not affected
SUSE Manager Proxy 4.3 s390-tools Not affected
SUSE Manager Proxy 4.3 sccache Not affected
SUSE Manager Retail Branch Server 4.3 aardvark-dns Not affected
SUSE Manager Retail Branch Server 4.3 aws-nitro-enclaves-cli Not affected
SUSE Manager Retail Branch Server 4.3 gstreamer-plugins-rs Not affected
SUSE Manager Retail Branch Server 4.3 netavark Not affected
SUSE Manager Retail Branch Server 4.3 rustup Not affected
SUSE Manager Retail Branch Server 4.3 s390-tools Not affected
SUSE Manager Retail Branch Server 4.3 sccache Not affected
SUSE Manager Server 4.3 aardvark-dns Not affected
SUSE Manager Server 4.3 aws-nitro-enclaves-cli Not affected
SUSE Manager Server 4.3 gstreamer-plugins-rs Not affected
SUSE Manager Server 4.3 netavark Not affected
SUSE Manager Server 4.3 rustup Not affected
SUSE Manager Server 4.3 s390-tools Not affected
SUSE Manager Server 4.3 sccache Not affected
Products under Long Term Service Pack support and receiving important and critical security fixes.
SUSE Linux Enterprise Desktop 15 SP4 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Desktop 15 SP4 rustup Not affected
SUSE Linux Enterprise Desktop 15 SP4 s390-tools Not affected
SUSE Linux Enterprise Desktop 15 SP4 sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP2 s390-tools Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3 rustup Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3 s390-tools Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3 sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS aardvark-dns Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS netavark Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS rustup Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS aardvark-dns Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS netavark Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS rustup Not affected
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4 aardvark-dns Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4 netavark Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4 rustup Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4 s390-tools Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4 sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS aardvark-dns Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS gstreamer-plugins-rs Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS netavark Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS rustup Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS aardvark-dns Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS gstreamer-plugins-rs Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS netavark Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS rustup Not affected
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS sccache Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP2 s390-tools Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP3 s390-tools Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP4 s390-tools Not affected
SUSE Linux Enterprise Module for Containers 15 SP4 aardvark-dns Not affected
SUSE Linux Enterprise Module for Containers 15 SP4 netavark Not affected
SUSE Linux Enterprise Module for Desktop Applications 15 SP4 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Module for Development Tools 15 SP3 rustup Not affected
SUSE Linux Enterprise Module for Development Tools 15 SP3 sccache Not affected
SUSE Linux Enterprise Module for Development Tools 15 SP4 rustup Not affected
SUSE Linux Enterprise Module for Development Tools 15 SP4 sccache Not affected
SUSE Linux Enterprise Module for Public Cloud 15 SP4 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Server 15 SP2 s390-tools Not affected
SUSE Linux Enterprise Server 15 SP2-LTSS s390-tools Not affected
SUSE Linux Enterprise Server 15 SP3 rustup Not affected
SUSE Linux Enterprise Server 15 SP3 s390-tools Not affected
SUSE Linux Enterprise Server 15 SP3 sccache Not affected
SUSE Linux Enterprise Server 15 SP3-LTSS aardvark-dns Not affected
SUSE Linux Enterprise Server 15 SP3-LTSS netavark Not affected
SUSE Linux Enterprise Server 15 SP3-LTSS rustup Not affected
SUSE Linux Enterprise Server 15 SP3-LTSS s390-tools Not affected
SUSE Linux Enterprise Server 15 SP3-LTSS sccache Not affected
SUSE Linux Enterprise Server 15 SP4 aardvark-dns Not affected
SUSE Linux Enterprise Server 15 SP4 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Server 15 SP4 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Server 15 SP4 netavark Not affected
SUSE Linux Enterprise Server 15 SP4 rustup Not affected
SUSE Linux Enterprise Server 15 SP4 s390-tools Not affected
SUSE Linux Enterprise Server 15 SP4 sccache Not affected
SUSE Linux Enterprise Server 15 SP4-LTSS aardvark-dns Not affected
SUSE Linux Enterprise Server 15 SP4-LTSS gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Server 15 SP4-LTSS netavark Not affected
SUSE Linux Enterprise Server 15 SP4-LTSS rustup Not affected
SUSE Linux Enterprise Server 15 SP4-LTSS s390-tools Not affected
SUSE Linux Enterprise Server 15 SP4-LTSS sccache Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP2 s390-tools Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP3 aardvark-dns Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP3 netavark Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP3 rustup Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP3 s390-tools Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP3 sccache Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 aardvark-dns Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 aws-nitro-enclaves-cli Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 netavark Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 rustup Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 s390-tools Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP4 sccache Not affected
Products past their end of life and not receiving proactive updates anymore.
SUSE Enterprise Storage 6 s390-tools Not affected
SUSE Enterprise Storage 7 s390-tools Not affected
SUSE Linux Enterprise Desktop 15 s390-tools Not affected
SUSE Linux Enterprise Desktop 15 SP1 s390-tools Not affected
SUSE Linux Enterprise Desktop 15 SP2 s390-tools Not affected
SUSE Linux Enterprise Desktop 15 SP3 rustup Not affected
SUSE Linux Enterprise Desktop 15 SP3 s390-tools Not affected
SUSE Linux Enterprise Desktop 15 SP3 sccache Not affected
SUSE Linux Enterprise High Performance Computing 15 s390-tools Not affected
SUSE Linux Enterprise High Performance Computing 15 SP1 s390-tools Not affected
SUSE Linux Enterprise Module for Basesystem 15 s390-tools Not affected
SUSE Linux Enterprise Module for Basesystem 15 SP1 s390-tools Not affected
SUSE Linux Enterprise Real Time 15 SP3 rustup Not affected
SUSE Linux Enterprise Real Time 15 SP3 sccache Not affected
SUSE Linux Enterprise Real Time 15 SP4 gstreamer-plugins-rs Not affected
SUSE Linux Enterprise Real Time 15 SP4 rustup Not affected
SUSE Linux Enterprise Real Time 15 SP4 sccache Not affected
SUSE Linux Enterprise Server 11 SP4 s390-tools Not affected
SUSE Linux Enterprise Server 11 SP4 LTSS s390-tools Not affected
SUSE Linux Enterprise Server 11 SP4-LTSS s390-tools Not affected
SUSE Linux Enterprise Server 12 SP4 s390-tools Not affected
SUSE Linux Enterprise Server 12 SP4-LTSS s390-tools Not affected
SUSE Linux Enterprise Server 15 s390-tools Not affected
SUSE Linux Enterprise Server 15 SP1 s390-tools Not affected
SUSE Linux Enterprise Server 15 SP1-LTSS s390-tools Not affected
SUSE Linux Enterprise Server 15 SP3-BCL rustup Not affected
SUSE Linux Enterprise Server 15 SP3-BCL sccache Not affected
SUSE Linux Enterprise Server 15-LTSS s390-tools Not affected
SUSE Linux Enterprise Server for SAP Applications 15 s390-tools Not affected
SUSE Linux Enterprise Server for SAP Applications 15 SP1 s390-tools Not affected
SUSE Manager Proxy 4.0 s390-tools Not affected
SUSE Manager Proxy 4.1 s390-tools Not affected
SUSE Manager Proxy 4.2 rustup Not affected
SUSE Manager Proxy 4.2 s390-tools Not affected
SUSE Manager Proxy 4.2 sccache Not affected
SUSE Manager Retail Branch Server 4.0 s390-tools Not affected
SUSE Manager Retail Branch Server 4.1 s390-tools Not affected
SUSE Manager Retail Branch Server 4.2 rustup Not affected
SUSE Manager Retail Branch Server 4.2 s390-tools Not affected
SUSE Manager Retail Branch Server 4.2 sccache Not affected
SUSE Manager Server 4.0 s390-tools Not affected
SUSE Manager Server 4.1 s390-tools Not affected
SUSE Manager Server 4.2 rustup Not affected
SUSE Manager Server 4.2 s390-tools Not affected
SUSE Manager Server 4.2 sccache Not affected
Container Status
suse/manager/5.0/x86_64/server-attestation snpguestNot affected


SUSE Timeline for this CVE

CVE page created: Wed Mar 6 23:00:11 2024
CVE page last modified: Mon Apr 29 19:17:29 2024