A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading…
高危 CVSS 7.8
摘要
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
- :
Lint 边界警告 (6)
以下是本次研判 lint 阶段发现的非阻塞性警告(如引用 URL 未在白名单内)。这些不影响漏洞条目可用性,仅为透明度披露(参 DR-002)。
-
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://kernel.dance/#04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://kernel.dance/#04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 -
REF_URL_NOT_ALLOWLISTEDurl not in allowlist: https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc
数据来源
- NVD DATABASE
原始链接
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 Patch
- https://kernel.dance/#04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 Exploit
- https://security.netapp.com/advisory/ntap-20220506-0007/ Third Party Advisory
- https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc Exploit
- http://packetstormsecurity.com/files/167386/Kernel-Live-Patch-Security-Notice-LSN-0086-1.html Third Party Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 Patch
- https://kernel.dance/#04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 Exploit
- https://security.netapp.com/advisory/ntap-20220506-0007/ Third Party Advisory
- https://syzkaller.appspot.com/bug?id=2212474c958978ab86525fe6832ac8102c309ffc Exploit
时间线
- nvd_ingest NVD