In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree …
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer allocated in software stack. Calling kfree on it causes undefined behaviour in subsequent operations.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/5944de192663f272033501dcd322b008fca72006 Mailing List
- https://git.kernel.org/stable/c/d7f01649f4eaf1878472d3d3f480ae1e50d98f6c Mailing List
- https://git.kernel.org/stable/c/5944de192663f272033501dcd322b008fca72006 Mailing List
- https://git.kernel.org/stable/c/d7f01649f4eaf1878472d3d3f480ae1e50d98f6c Mailing List
Timeline
- nvd_ingest NVD