Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12210
HistoryJan 15, 2019 - 9:14 a.m.

Arbitrary Code Execution

2019-01-1509:14:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
24

EPSS

0.817

Percentile

98.4%

kernel-rt is vulnerable to arbitrary code execution attacks. The vulnerability exists as a race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka “Dirty COW.”

References