In the Linux kernel, the following... CVE-2022-48771

- AV AC AU C I A
发布: 2024-06-20
修订: 2025-01-06

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix stale file descriptors on failed usercopy A failing usercopy of the fence_rep object will lead to a stale entry in the file descriptor table as put_unused_fd() won't release it. This enables userland to refer to a dangling 'file' object through that still valid file descriptor, leading to all kinds of use-after-free exploitation scenarios. Fix this by deferring the call to fd_install() until after the usercopy has succeeded.

0%
暂无可用Exp或PoC
当前有7条受影响产品信息