Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35mj-6q95-hqwx

Опубликовано: 26 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer.

An unprivileged local user can exploit this use-after-free to escalate privileges.

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer.

An unprivileged local user can exploit this use-after-free to escalate privileges.

EPSS

Процентиль: 3%
0.00134
Низкий

7.8 High

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 7.8
nvd
11 дней назад

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user can exploit this use-after-free to escalate privileges.

EPSS

Процентиль: 3%
0.00134
Низкий

7.8 High

CVSS3

Дефекты

CWE-416