In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709. This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an attacker can bypass intended restrictions on adding an IPv4 address to the loopback interface. This occurs because IORING_OP_SENDMSG operations, although requested in the context of an unprivileged user, are sometimes performed by a kernel worker thread without considering that context.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Dec 17, 2019 |
| Suse | — | Upgrade kernel-default | Feb 4, 2022 | Dec 17, 2019 |
| Ubuntu | — | Upgrade linux-image-5.3.0-1012-gcpUpgrade linux-image-kvmUpgrade linux-image-generic-hwe-18.04Upgrade linux-image-virtual-hwe-18.04Upgrade linux-image-lowlatency-hwe-18.04Upgrade linux-image-5.3.0-40-lowlatencyUpgrade linux-image-gcp-edgeUpgrade linux-image-awsUpgrade linux-image-generic-lpaeUpgrade linux-image-5.3.0-1009-oracleUpgrade linux-image-oracleUpgrade linux-image-raspi2-hwe-18.04Upgrade linux-image-virtualUpgrade linux-image-snapdragon-hwe-18.04Upgrade linux-image-5.3.0-40-generic-lpaeUpgrade linux-image-5.3.0-40-snapdragonUpgrade linux-image-azure-edgeUpgrade linux-image-gcpUpgrade linux-image-raspi2Upgrade linux-image-gkeUpgrade linux-image-5.3.0-1018-raspi2Upgrade linux-image-5.3.0-1013-azureUpgrade linux-image-5.3.0-1011-awsUpgrade linux-image-azureUpgrade linux-image-genericUpgrade linux-image-5.3.0-40-genericUpgrade linux-image-generic-lpae-hwe-18.04Upgrade linux-image-5.3.0-1010-kvmUpgrade linux-image-lowlatencyUpgrade linux-image-snapdragon | Feb 19, 2020 | Dec 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub