Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xq4-8c55-jfwq

Опубликовано: 23 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859

EPSS

Процентиль: 19%
0.0027
Низкий

7.8 High

CVSS3

Дефекты

CWE-415

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859

CVSS3: 7.5
nvd
около 4 лет назад

io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading the kernel past commit df3f3bb5059d20ef094d6b2f0256c4bf4127a859

CVSS3: 7.5
debian
около 4 лет назад

io_uring use work_flags to determine which identity need to grab from ...

CVSS3: 7.8
fstec
около 4 лет назад

Уязвимость ядра операционной системы Linux, связанная с повторным освобождением памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.0027
Низкий

7.8 High

CVSS3

Дефекты

CWE-415