Vulnerability in the io_uring subsystem of the Linux kernel allows privilege escalation.

A vulnerability (CVE-2021-41073) has been discovered in the Linux kernel, enabling a local user to escalate their privileges in the system. This issue stems from an error in the implementation of the io_uring asynchronous I/O interface, leading to access to a previously freed block of memory. It has been noted that the researcher managed to achieve memory release at a specified offset by manipulating the loop_rw_iter() function from a non-privileged user's perspective, making it possible to create a functional exploit. The issue has only been addressed in the form of a patch that has been backported to the stable branches of the kernel, but the update has not yet been released.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster