In the Linux kernel, the following vulnerability has been resolved: hsr: hold rcu and dev lock for hsr_get_port_ndev hsr_get_port_ndev calls hsr_for_each_port, which need to hold rcu lock. On the o…
高危 CVSS 7.8
摘要
In the Linux kernel, the following vulnerability has been resolved: hsr: hold rcu and dev lock for hsr_get_port_ndev hsr_get_port_ndev calls hsr_for_each_port, which need to hold rcu lock. On the other hand, before return the port device, we need to hold the device reference to avoid UaF in the caller function.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/68a6729afd3e8e9a2a32538642ce92b96ccf9b1d Patch
- https://git.kernel.org/stable/c/847748fc66d08a89135a74e29362a66ba4e3ab15 Patch
- https://git.kernel.org/stable/c/9433ba79c2ec3ec7c9a711748701549339c3438c
时间线
- nvd_ingest NVD