Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8w8-4f3f-5v3j

Опубликовано: 05 мар. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

EPSS

Процентиль: 1%
0.00011
Низкий

7 High

CVSS3

Дефекты

CWE-362
CWE-416

Связанные уязвимости

CVSS3: 7
ubuntu
больше 3 лет назад

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

CVSS3: 6.7
redhat
почти 4 года назад

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

CVSS3: 7
nvd
больше 3 лет назад

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

CVSS3: 7
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7
debian
больше 3 лет назад

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kern ...

EPSS

Процентиль: 1%
0.00011
Низкий

7 High

CVSS3

Дефекты

CWE-362
CWE-416