Database/Kernel, userspace & hypervisor
Linux kernel (io_uring): Page use-after-free via io_uring buffer-ring mmap - unprivileged local user to root
CVSS 7.8CVE-2024-0582Kernel, userspace & hypervisorcurated
Impact
Page use-after-free via io_uring buffer-ring mmap - unprivileged local user to root
Who can reach it
Any tenant process in a container with io_uring enabled
What to do
Livepatchable; otherwise drain + reboot. Or disable io_uring for tenant containers
References
Related entries
- Linux kernel (io_uring): Use-after-free between io_uring and the unix GC - local rootCVE-2022-2602 · Linux kernel (io_uring)High
- Linux kernel (io_uring): io_uring fixed-buffer registration gives out-of-bounds access to physical memoryCVE-2023-2598 · Linux kernel (io_uring)High
- Linux kernel (nf_tables): Use-after-free in nft_verdict_init() - double-free to local rootCVE-2024-1086 · Linux kernel (nf_tables)High
- Linux kernel (ksmbd): Use-after-free in ksmbd_tcp_new_connection() - in-kernel SMB serverCVE-2024-26592 · Linux kernel (ksmbd)High
- Linux kernel (drivers/iommu/iommufd): On a partially-failed access attach, iommufd overwrites the xarray id that tracksCVE-2024-26786 · Linux kernel (drivers/iommu/iommufd)High
- Linux kernel (drivers/vfio/pci): A tenant races a DisINTx write to emulated config space against a SET_IRQS ioctl, soCVE-2024-26810 · Linux kernel (drivers/vfio/pci)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.