Total vulnerabilities in the database
A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 9.0 | 9.0.x |
fedoraproject / fedora | 34 | 34.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |
canonical / ubuntu_linux | 20.04 | 20.04.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 21.10 | 21.10.x |
linux / linux_kernel | 5.11 | 5.14.19 |
linux / linux_kernel | 5.15 | 5.15.3 |
linux / linux_kernel | 5.5.0 | 5.10.80 |
linux / linux_kernel | 4.20 | 5.4.160 |
linux / linux_kernel | 4.10 | 4.14.256 |
linux / linux_kernel | 4.5 | 4.9.291 |
linux / linux_kernel | 4.15 | 4.19.218 |
linux / linux_kernel | - | 4.4.293 |