Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
bpf: Guard __get_user acesss with access_ok for uprobe_multi data
As reported by sashiko [1] we need to use access_ok to check the user space data bounds before we use __get-user to get it.
Details
- Affected product:
- Debian 10 ELS
- Affected packages:
- linux @ 4.19.0