USN-7234-4: Linux kernel (AWS) vulnerabilities

Post Reply
Shane1145
Posts: 1189
Joined: Wed Sep 25, 2024 2:31 pm

USN-7234-4: Linux kernel (AWS) vulnerabilities

Post by Shane1145 »

Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux kernel did not properly handle locking for rings with IOPOLL, leading to a
double-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
(CVE-2023-21400)


https://ubuntu.com/security/notices/USN-7234-4
Post Reply