Dismissed
(max. allowed matches exceeded)
Activity log
- Created & dismissed (max. allowed matches exceeded) suggestion
liveupdate: fix TOCTOU race in luo_session_retrieve()
In the Linux kernel, the following vulnerability has been resolved: liveupdate: fix TOCTOU race in luo_session_retrieve() Extend the scope of the rwsem_read lock in luo_session_retrieve() to overlap with the acquisition of the session mutex. This prevents a concurrent thread from releasing and freeing the session between the lookup and the mutex lock.
References
Affected products
Linux
- <d944170607b872a1f93713c555ad3f0efde3a9b8
- =<*
- ==6.19
- =<7.1.*
- <6.19
- <d3ae9e7fddb4036f50003d7fa1ef52801fdb961b