Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29506
HistoryFeb 26, 2021 - 2:13 a.m.

Privilege Escalation

2021-02-2602:13:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6
linux
kernel
vulnerability
io_uring
local attacker
privilege escalation
denial of service
file reference counter
arbitrary code execution
software

EPSS

0.007

Percentile

81.0%

linux kernel is vulnerable to arbitrary code execution. A use-after-free in the io_uring where a local attacker with a user privilege is able to cause a denial of service condition on the system and potentially obtain higher privileges due to the lack of validation of the existence of an object prior to performing operations on the object by not incrementing the file reference counter while in use.

EPSS

0.007

Percentile

81.0%