Описание
A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.
Отчет
The use-after-free flaw in PackageKitd is categorized as a low vulnerability rather than moderate because the conditions required for exploitation are not as immediate or straightforward. While the flaw does pose a security risk by potentially allowing unauthorized memory access, the impact and ease of exploitation are deemed to be lower compared to vulnerabilities labeled as moderate. The low rating suggests that although attention and remediation are necessary, the risk is not as severe or immediately exploitable as higher-rated vulnerabilities.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | PackageKit | Out of support scope | ||
| Red Hat Enterprise Linux 7 | compat-PackageKit08 | Out of support scope | ||
| Red Hat Enterprise Linux 7 | PackageKit | Out of support scope | ||
| Red Hat Enterprise Linux 8 | PackageKit | Fix deferred | ||
| Red Hat Enterprise Linux 9 | PackageKit | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.
A use-after-free flaw was found in PackageKitd. In some conditions, the order of cleanup mechanics for a transaction could be impacted. As a result, some memory access could occur on memory regions that were previously freed. Once freed, a memory region can be reused for other allocations and any previously stored data in this memory region is considered lost.
A use-after-free flaw was found in PackageKitd. In some conditions, th ...
EPSS
3.3 Low
CVSS3