Back to bug 1403747

Who When What Removed Added
Vladis Dronov 2016-12-12 10:23:05 UTC Blocks 1395250
Vladis Dronov 2016-12-12 10:28:12 UTC Doc Text Use-after-free vulnerability in the ffs_user_copy_worker function in drivers/usb/gadget/function/f_fs.c in the Linux kernel before 4.5.3 allows local users to gain privileges by accessing an I/O data structure after a certain callback call. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although we believe it is unlikely.
Doc Type If docs needed, set a value Bug Fix
Vladis Dronov 2016-12-12 10:30:10 UTC Depends On 1403752
PnT Account Manager 2018-02-07 23:22:31 UTC CC agordeev
PnT Account Manager 2018-07-19 06:23:33 UTC CC mguzik
PnT Account Manager 2018-08-28 22:11:13 UTC CC lwang
Eric Sammons 2019-02-08 14:59:52 UTC CC esammons
PnT Account Manager 2019-02-28 22:31:23 UTC CC jkastner
Product Security DevOps Team 2019-09-29 14:02:45 UTC Whiteboard impact=moderate,public=20160414,reported=20160414,source=git,cvss2=9.3/AV:N/AC:M/Au:N/C:C/I:C/A:C,cvss3=7.8/CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H,cwe=CWE-416,rhel-5/kernel=notaffected,rhel-6/kernel=notaffected,rhel-7/kernel=notaffected,rhel-7/kernel-rt=notaffected,mrg-2/realtime-kernel=notaffected,rhelsa-7/arm-kernel=affected,fedora-all/kernel=notaffected
PnT Account Manager 2020-01-17 22:31:52 UTC CC labbott
Jeff Fearn 🐞 2020-05-07 08:11:12 UTC CC arm-mgr
Joey Boggs 2020-09-15 18:43:40 UTC CC plougher
Red Hat Bugzilla 2021-03-23 23:39:12 UTC CC matt
Red Hat Bugzilla 2021-05-30 12:36:38 UTC CC bhu
Jeff Fearn 🐞 2021-06-03 11:56:45 UTC CC bhu
Joshua Padman 2021-10-27 10:51:49 UTC Resolution --- ERRATA
Status NEW CLOSED
Last Closed 2021-10-27 10:51:49 UTC

Back to bug 1403747