Vulnerability identifier: #VU91209
Vulnerability risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-119
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Linux kernel
Operating systems & Components /
Operating system
Vendor: Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the mhi_del_ring_element() function in drivers/bus/mhi/host/main.c. A local user can escalate privileges on the system.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Linux kernel: All versions
External links
https://git.kernel.org/stable/c/94991728c84f8df54fd9eec9b85855ef9057ea08
https://git.kernel.org/stable/c/2df39ac8f813860f79782807c3f7acff40b3c551
https://git.kernel.org/stable/c/a9ebfc405fe1be145f414eafadcbf09506082010
https://git.kernel.org/stable/c/ecf8320111822a1ae5d5fc512953eab46d543d0b
https://git.kernel.org/stable/c/eff9704f5332a13b08fbdbe0f84059c9e7051d5f
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.