Kernel Live Patch Security Notice LSN-0086-1

Discussion in 'News Aggregator' started by Packet Storm, 4 Jun 2022.

  1. Packet Storm

    Packet Storm Guest

    It was discovered that a race condition existed in the network scheduling subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...