Hide Forgot
The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation. This is related to blk_mq_free_rqs and blk_cleanup_queue. Reference and upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c3e2219216c92919a6bd1711f340f5faa98695e6
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1961293]
This was fixed for Fedora with the 5.2 stable kernel rebases.