Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2j9-jf3f-5hc2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

EPSS

Процентиль: 22%
0.00068
Низкий

7 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7
ubuntu
почти 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

CVSS3: 5.1
redhat
почти 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

CVSS3: 7
nvd
почти 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.

CVSS3: 7
debian
почти 6 лет назад

In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is ...

suse-cvrf
почти 6 лет назад

Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP1)

EPSS

Процентиль: 22%
0.00068
Низкий

7 High

CVSS3

Дефекты

CWE-362