Linux 6.6 Race Condition

Discussion in 'News Aggregator' started by Packet Storm, 23 Nov 2024.

  1. Packet Storm

    Packet Storm Guest

    A security-relevant race between mremap() and THP code has been discovered. Reaching the buggy code typically requires the ability to create unprivileged namespaces. The bug leads to installing physical address 0 as a page table, which is likely exploitable in several ways: For example, triggering the bug in multiple processes can probably lead to unintended page table sharing, which probably can lead to stale TLB entries pointing to freed pages.

    Continue reading...
     

Share This Page

Loading...