Description


In DevmemIntUnexportCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

Related CPE's


Vulnerable

Weaknesses



CWE-362

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-269CWE-284

CVSS impact metrics


CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

7 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-07-09T19:15:14.593Z

1 year ago

Last modified

2024-12-17T17:14:22.923Z

1 year ago