In the Linux kernel before 5.17.3, fs/io_uring.c has a...
High severity
Unreviewed
Published
Apr 23, 2022
to the GitHub Advisory Database
•
Updated May 11, 2024
Description
Published by the National Vulnerability Database
Apr 22, 2022
Published to the GitHub Advisory Database
Apr 23, 2022
Last updated
May 11, 2024
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.
References