In the Linux kernel, the following vulnerability has been resolved: block, bfq: don't move oom_bfqq Our test report a UAF: [ 2073.019181] ==========================================================…
High CVSS 7.8
Summary
In the Linux kernel, the following vulnerability has been resolved: block, bfq: don't move oom_bfqq Our test report a UAF: [ 2073.019181] ================================================================== [ 2073.019188] BUG: KASAN: use-after-free in __bfq_put_async_bfqq+0xa0/0x168 [ 2073.019191] Write of size 8 at addr ffff8000ccf64128 by task rmmod/72584 [ 2073.019192] [ 2073.019196] CPU: 0 PID: 72584 Comm: rmmod Kdump: loaded Not tainted 4.19.90-yk #5 [ 2073.019198] Hardware name: QEMU KVM…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/7507ead1e9d42957c2340f2c4a0e9d00034e3366 Patch
- https://git.kernel.org/stable/c/8410f70977734f21b8ed45c37e925d311dfda2e7 Patch
- https://git.kernel.org/stable/c/87fdfe8589d43e471dffb4c60f75eeb6f37afc4c Patch
- https://git.kernel.org/stable/c/8f34dea99cd7761156a146a5258a67d045d862f7 Patch
- https://git.kernel.org/stable/c/c01fced8d38fbccc82787065229578006f28e020 Patch
- https://git.kernel.org/stable/c/c4f5a678add58a8a0e7ee5e038496b376ea6d205 Patch
Timeline
- nvd_ingest NVD