Описание
In the Linux kernel, the following vulnerability has been resolved:
USB: gadget: ffs: fix mm lifetime handling
io_data stores a pointer to the submitting task's mm_struct, but does not currently hold a reference to it while async requests are pending.
This can result in a use-after-free if the task exits before completion handling finishes.
Take a reference with mmgrab() when queuing the read request and release it with mmdrop() on request completion.
EPSS
7.8 High
CVSS3
Дефекты
Связанные уязвимости
(In the Linux kernel, the following vulnerability has been resolved: U ...)
In the Linux kernel, the following vulnerability has been resolved: U ...
In the Linux kernel, the following vulnerability has been resolved: USB: gadget: ffs: fix mm lifetime handling io_data stores a pointer to the submitting task's mm_struct, but does not currently hold a reference to it while async requests are pending. This can result in a use-after-free if the task exits before completion handling finishes. Take a reference with mmgrab() when queuing the read request and release it with mmdrop() on request completion.
EPSS
7.8 High
CVSS3