Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 3 weeks, 4 days ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
VDUSE: avoid leaking information to userspace

In the Linux kernel, the following vulnerability has been resolved: VDUSE: avoid leaking information to userspace The bounceing is not necessarily page aligned, so current VDUSE can leak kernel information through mapping bounce pages to userspace. Allocate bounce pages with __GFP_ZERO to avoid leaking information to userspace.

Affected products

Linux
  • <5.15
  • =<6.6.*
  • <9c1523803445ee0348f62b77793266dd981596e0
  • =<*
  • <fde25641cbddd0c084e3320d08f755e7e6acfae5
  • ==5.15
  • =<6.18.*
  • <690fb82c4122f8c2656fa4f842275132771b68b9
  • =<6.12.*
  • =<7.1.*
  • <00335df9da2011e095f846d645cc2e9fd2907659
  • <5e88c1bc3a41d9a260dd42bae8ad18fd4f35bbe1