Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-46937
HistoryFeb 27, 2024 - 12:00 a.m.

CVE-2021-46937

2024-02-2700:00:00
ubuntu.com
ubuntu.com
8
linux kernel
vulnerability
resolved
dbgfs_target_ids_write.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

In the Linux kernel, the following vulnerability has been resolved:
mm/damon/dbgfs: fix ‘struct pid’ leaks in ‘dbgfs_target_ids_write()’ DAMON
debugfs interface increases the reference counts of 'struct pid’s for
targets from the ‘target_ids’ file write callback
(‘dbgfs_target_ids_write()’), but decreases the counts only in DAMON
monitoring termination callback (‘dbgfs_before_terminate()’). Therefore,
when ‘target_ids’ file is repeatedly written without DAMON monitoring
start/termination, the reference count is not decreased and therefore
memory for the ‘struct pid’ cannot be freed. This commit fixes this issue
by decreasing the reference counts when ‘target_ids’ is written.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%