CVE-2024-50080

10/29/2024 1:15:00 AM
2 ماه قبل
2 ماه قبل
7
Reporter :cve@kernel.org
Modified :10/29/2024 1:15:00 AM
Problem Data :NVD-CWE-noinfo

Description

In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on ublk char device for filling request buffer, and unprivileged device can't be trusted. So don't allow user copy for unprivileged device.

Cvss Version 3.1

5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact None
Availability Impact High