In the Linux kernel, the following vulnerability has been resolved:
ublk: don't allow user copy for unprivileged device
UBLK_F_USER_COPY requires userspace to call write() on ublk char
device for filling request buffer, and unprivileged device can't
be trusted.
So don't allow user copy for unprivileged device.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-10-29 01:15
Updated : 2024-10-30 15:54
NVD link : CVE-2024-50080
Mitre link : CVE-2024-50080
CVE.ORG link : CVE-2024-50080
JSON object : View
Products Affected
linux
- linux_kernel
CWE