REDHAT-BUG-1786164: Use After Free

Published Dec 23, 2019
·
Updated

A use-after-free flaw was found in the Linux kernels implementation of blktrace in the blkaddtrace function. A local attacker with permissions to run block trace instructions against a device can create a situation where the core blocktrace object is used after it is freed. The attacker can pre-groom memory to race this use-after-free to create a condition where memory is corrupted and also likely to be privilege escalation.

The ability to create this condition requires elevated privileges, and it has been decided that this change in Red Hat Enterprise Linux 5 and 6 would risk introducing possible regressions and will not be backported.

Reference: https://bugzilla.kernel.org/showbug.cgi?id=205711

Patch: A patch may be attached to the bugzilla.kernel.org but no patch exists at this time.

Affected Software

1 affected component
Red Hat Enterprise Linux<6

Event History

Dec 23, 2019
Data Sourced
via Red Hat·05:30 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1786164?

The severity of REDHAT-BUG-1786164 is considered critical due to the potential for local attackers to exploit the use-after-free flaw.

2

How do I fix REDHAT-BUG-1786164?

To address REDHAT-BUG-1786164, apply the latest security updates provided by Red Hat for affected versions of the Enterprise Linux.

3

Who is affected by REDHAT-BUG-1786164?

Users of Red Hat Enterprise Linux version 6 and below who run block trace instructions are at risk from REDHAT-BUG-1786164.

4

What potential impact does REDHAT-BUG-1786164 have?

Exploitation of REDHAT-BUG-1786164 may lead to privilege escalation and unauthorized access to system resources.

5

When was REDHAT-BUG-1786164 reported?

REDHAT-BUG-1786164 was reported on July 23, 2020, highlighting its critical nature to users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203