Описание
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this.
An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
8.4 High
CVSS3
Дефекты
Связанные уязвимости
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations are not permitted on largepage objects, but the implementation did not verify this. An unprivileged local user can abuse the bug to access freed kernel memory. This can be exploited to escalate privileges.
Уязвимость реализации объектов разделяемой памяти largepage ядра операционных систем FreeBSD, позволяющая нарушителю повысить свои привилегии
EPSS
8.4 High
CVSS3