Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestions search

With package: linuxKernel.packages.linux_xanmod_stable.cryptodev

Found 1 matching suggestions

View:
Compact
Detailed
created 3 weeks, 3 days ago
cryptodev-linux <= 1.14 get_userbuf Use After Free LPE

cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation.

Affected products

cryptodev-linux
  • =<1.14

Matching in nixpkgs

Package maintainers