mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move.
2022-09-21T08:15:09.047
2025-05-28T16:15:28.580
Modified
CVSSv3.1: 7.0 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | linux | linux_kernel | < 5.4.211 | Yes |
Operating System | linux | linux_kernel | < 5.10.137 | Yes |
Operating System | linux | linux_kernel | < 5.12.18 | Yes |
Operating System | linux | linux_kernel | < 5.13.3 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Application | netapp | hci_baseboard_management_controller | h300s | Yes |
Application | netapp | hci_baseboard_management_controller | h410c | Yes |
Application | netapp | hci_baseboard_management_controller | h410s | Yes |
Application | netapp | hci_baseboard_management_controller | h500s | Yes |
Application | netapp | hci_baseboard_management_controller | h700s | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 20.04 | Yes |
Operating System | canonical | ubuntu_linux | 22.04 | Yes |