In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet transmission, if the system is under heavy load, the h…
Critical CVSS 9.8
Summary
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet transmission, if the system is under heavy load, the hardware might complete processing the packet and free the request memory (req) before the transmission function finishes. If the software subsequently accesses this req, a use-after-free error will occur. The qp_ctx memory exists throughout the packet sending process, so replace the req with the qp_…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/67b53a660e6bf0da2fa8d8872e897a14d8059eaf Patch
- https://git.kernel.org/stable/c/ad73563f3a1edbfddf2724136c6a15826b354e18 Patch
- https://git.kernel.org/stable/c/b375c3c7209cc59e40e97998aa9bc768369cca0e Patch
Timeline
- nvd_ingest NVD