In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily page aligned, so current VDUSE can leak kernel inf…
Info
Summary
In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily page aligned, so current VDUSE can leak kernel information through mapping bounce pages to userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking information to userspace.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/00335df9da2011e095f846d645cc2e9fd2907659
- https://git.kernel.org/stable/c/3ae878f262bd1445c8c31511856a99962a05fe16
- https://git.kernel.org/stable/c/41e27a6aca608c9e04f091c29c420d03fafe0313
- https://git.kernel.org/stable/c/5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1
- https://git.kernel.org/stable/c/690fb82c4122f8c2656fa4f842275132771b68b9
- https://git.kernel.org/stable/c/9c1523803445ee0348f62b77793266dd981596e0
- https://git.kernel.org/stable/c/fde25641cbddd0c084e3320d08f755e7e6acfae5
Timeline
- nvd_ingest NVD