In the Linux kernel through 4.20.11, af_alg_release() in crypto/af_alg.c neglects to set a NULL value for a certain structure member, which leads to a use-after-free in sockfs_setattr.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.20 | 4.20.12 |
| linux / linux_kernel | 4.19 | 4.19.25 |
| linux / linux_kernel | 5.0-rc7 | 5.0-rc7.x |
| linux / linux_kernel | 5.0-rc1 | 5.0-rc1.x |
| linux / linux_kernel | 4.10 | 4.14.103 |
| linux / linux_kernel | 5.0-rc2 | 5.0-rc2.x |
| linux / linux_kernel | 5.0-rc3 | 5.0-rc3.x |
| linux / linux_kernel | 5.0-rc4 | 5.0-rc4.x |
| linux / linux_kernel | 5.0-rc5 | 5.0-rc5.x |
| linux / linux_kernel | 5.0-rc6 | 5.0-rc6.x |
| linux / linux_kernel | 5.0-rc8 | 5.0-rc8.x |
| redhat / enterprise_linux | 7.0 | 7.0.x |
| canonical / ubuntu_linux | 18.04 | 18.04.x |
| canonical / ubuntu_linux | 18.10 | 18.10.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| opensuse / leap | 15.0 | 15.0.x |