In the Linux kernel, the following vulnerability has been resolved: vdpa: fix use-after-free on vpvdparemove When vpvdpa driver is unbind, vpvdpa is freed in vdpaunregisterdevice and then vpvdpa->mdev.pcidev is dereferenced in vpmodernremove, triggering use-after-free. Call Trace of unbinding driver free vpvdpa : dosyscall64 vfswrite kernfsfopwriteiter devicereleasedriverinternal pcideviceremove vpvdparemove vdpaunregisterdevice kobjectrelease devicerelease kfree Call Trace of dereference vpvdpa->mdev.pcidev: vpmodernremove pcireleaseselectedregions pcireleaseregion pciresourcelen pciresource_end (dev)->resource[(bar)].end
{ "availability": "No subscription required", "binaries": [ { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-buildinfo-5.15.0-1008-intel-iotg" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-cloud-tools-5.15.0-1008-intel-iotg" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-headers-5.15.0-1008-intel-iotg" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-image-unsigned-5.15.0-1008-intel-iotg" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-image-unsigned-5.15.0-1008-intel-iotg-dbgsym" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-intel-iotg-5.15-cloud-tools-5.15.0-1008" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-intel-iotg-5.15-cloud-tools-common" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-intel-iotg-5.15-headers-5.15.0-1008" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-intel-iotg-5.15-tools-5.15.0-1008" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-intel-iotg-5.15-tools-common" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-intel-iotg-5.15-tools-host" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-modules-5.15.0-1008-intel-iotg" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-modules-extra-5.15.0-1008-intel-iotg" }, { "binary_version": "5.15.0-1008.11~20.04.1", "binary_name": "linux-tools-5.15.0-1008-intel-iotg" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_version": "5.15.0-1007.7", "binary_name": "linux-buildinfo-5.15.0-1007-realtime" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-cloud-tools-5.15.0-1007-realtime" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-headers-5.15.0-1007-realtime" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-image-5.15.0-1007-realtime" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-modules-5.15.0-1007-realtime" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-modules-extra-5.15.0-1007-realtime" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-realtime-cloud-tools-5.15.0-1007" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-realtime-cloud-tools-common" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-realtime-headers-5.15.0-1007" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-realtime-tools-5.15.0-1007" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-realtime-tools-common" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-realtime-tools-host" }, { "binary_version": "5.15.0-1007.7", "binary_name": "linux-tools-5.15.0-1007-realtime" } ] }