oss-sec mailing list archives

Re: CVE-2022-1419: Linux kernel: A concurrency use-after-free in vgem_gem_dumb_create


From: Greg KH <greg () kroah com>
Date: Thu, 21 Apr 2022 19:35:46 +0200

On Thu, Apr 21, 2022 at 11:44:54PM +0800, Minh Yuan wrote:
Timeline:
* 21.04.22 - Vulnerability reported to security () kernel org and
linux-distros () vs openwall org
* 21.04.22 - CVE-2022-1419 assigned.

Why are people assigning CVEs to things that require root permissions?
Or are there distros running on kernels older than 5.4 that allow
untrusted users access to the drm ioctls directly?

I'm curious as it would affect the backporting of the needed fixes here
(or not.)

thanks,

greg k-h


Current thread: