ALAS2-2024-2391 --- kernelID: oval:org.secpod.oval:def:1702036 | Date: (C)2024-02-07 (M)2024-04-29 |
Class: PATCH | Family: unix |
A race condition leading to a use-after-free issue was found in the QXL driver in the Linux kernel. A use-after-free vulnerability in the Linux kernel's ipv4: igmp component can be exploited to achieve local privilege escalation.A race condition can be exploited to cause a timer be mistakenly registered on a RCU read locked object which is freed by another thread.We recommend upgrading past commit e2b706c691905fe78468c361aaabc719d0a496f1
Product: |
kernel |
perf |
python-perf |