Vulnerability identifier: #VU104458
Vulnerability risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-416
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the nfc_unregister_device() function in net/nfc/core.c. A local user can escalate privileges on the system.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/1632be63862f183cd5cf1cc094e698e6ec005dfd
https://git.kernel.org/stable/c/1b0e81416a24d6e9b8c2341e22e8bf48f8b8bfc9
https://git.kernel.org/stable/c/2a1b5110c95e4d49c8c3906270dfcde680a5a7be
https://git.kernel.org/stable/c/4a68938f43b7c2663e4c90bb9bbe29ac8b9a42a0
https://git.kernel.org/stable/c/4f5d71930f41be78557f9714393179025baacd65
https://git.kernel.org/stable/c/6abfaca8711803d0d7cc8c0fac1070a88509d463
https://git.kernel.org/stable/c/a8e03bcad52dc9afabf650fdbad84f739cec9efa
https://git.kernel.org/stable/c/f81270125b50532624400063281e6611ecd61ddf
https://git.kernel.org/stable/c/fbf9c4c714d3cdeb98b6a18e4d057f931cad1d81
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.