Linux Dangling PFN Mapping / Use-After-Free

Discussion in 'News Aggregator' started by Packet Storm, 23 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    An error path in usbdev_mmap() (where remap_pfn_range() fails midway through) frees pages before the PFN mapping pointing to those pages is cleaned up, making physical page use-after-free possible. Some other drivers look like they might have similar issues.

    Continue reading...
     

Share This Page

Loading...