Описание
[GHSA-r2gm-p682-3mpm: svxreflector: use-after-free via reentrant client deletion]
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| svxlink | fixed | 26.05.1-1 | package | |
| svxlink | no-dsa | trixie | package |
Примечания
https://github.com/sm0svx/svxlink/security/advisories/GHSA-r2gm-p682-3mpm
Связанные уязвимости
ubuntu
16 дней назад
[GHSA-r2gm-p682-3mpm: svxreflector: use-after-free via reentrant client deletion]
redhat
около 2 месяцев назад
A flaw was found in svxlink's svxreflector component. A reentrant client deletion triggered via a sendError() write-failure path leads to a use-after-free on the client object. A remote attacker can trigger this condition to crash the reflector server or potentially achieve arbitrary code execution.