REDHAT-BUG-1786164: Use After Free
A use-after-free flaw was found in the Linux kernels implementation of blktrace in the blkaddtrace function. A local attacker with permissions to run block trace instructions against a device can create a situation where the core blocktrace object is used after it is freed. The attacker can pre-groom memory to race this use-after-free to create a condition where memory is corrupted and also likely to be privilege escalation.
The ability to create this condition requires elevated privileges, and it has been decided that this change in Red Hat Enterprise Linux 5 and 6 would risk introducing possible regressions and will not be backported.
Reference: https://bugzilla.kernel.org/showbug.cgi?id=205711
Patch: A patch may be attached to the bugzilla.kernel.org but no patch exists at this time.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1786164?
The severity of REDHAT-BUG-1786164 is considered critical due to the potential for local attackers to exploit the use-after-free flaw.
How do I fix REDHAT-BUG-1786164?
To address REDHAT-BUG-1786164, apply the latest security updates provided by Red Hat for affected versions of the Enterprise Linux.
Who is affected by REDHAT-BUG-1786164?
Users of Red Hat Enterprise Linux version 6 and below who run block trace instructions are at risk from REDHAT-BUG-1786164.
What potential impact does REDHAT-BUG-1786164 have?
Exploitation of REDHAT-BUG-1786164 may lead to privilege escalation and unauthorized access to system resources.
When was REDHAT-BUG-1786164 reported?
REDHAT-BUG-1786164 was reported on July 23, 2020, highlighting its critical nature to users.