| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Validate udata before executing commands
The destroy callbacks currently zero the udata output after tearing down
driver resources. If the userspace access fails, uverbs preserves the
uobject and allows the destroy callback to run again, even though the
driver resource has already been freed.
Call ib_no_udata_io() before teardown so udata failures are detected
while the resource is still intact, then return success after teardown
completes.
As part of this change, move ib_respond_empty_udata() to the start of
the create and modify flows. While this is not strictly required for
general create flows, as the core layer unwinds uobjects on failure, it
is necessary for create AH. In _rdma_create_ah(), the HW object is
otherwise leaked. |
| Use after free in Windows Modern Device Management (MDM) allows an authorized attacker to elevate privileges locally. |
| Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. |
| Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine |
| Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network. |
| Use after free in Windows Embedded Mode Service allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Push Notifications allows an authorized attacker to elevate privileges locally. |
| Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network. |
| Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. |
| Use After Free in GitHub repository vim/vim prior to 9.0.0322. |
| Use After Free in GitHub repository vim/vim prior to 9.0.0789. |
| Use After Free in GitHub repository vim/vim prior to 9.0.0579. |
| Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. |
| Use after free in Windows Audio Service allows an authorized attacker to elevate privileges locally. |