Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
audit: fix potential use-after-free in audit_del_rule()
audit_del_rule() destroys e->rule.exe via audit_remove_mark_rule()
before unlinking the rule from RCU-visible filter lists and waiting for a
grace period. Concurrent readers in audit_filter() and
audit_filter_rules() still dereference e->rule.exe, while the fsnotify
mark can be freed on an independent lifetime path. This creates a
use-after-free window during rule deletion.
Fix this by unlinking the rule from the RCU-visible lists and invoking
synchronize_rcu() before calling audit_remove_mark_rule() (and other
rule removal helpers). This ensures that all existing RCU readers have
exited the critical section before any underlying resources are destroyed.
Details
- Affected product:
- Debian 10 ELS , Debian 11 ELS , Ubuntu 16.04 ELS , Ubuntu 18.04 ELS , Ubuntu 20.04 ELS
- Affected packages:
- linux @ 4.4.0 (+5 more)
Fixes
KernelCare state
Live-patch status from KernelCare for each operating system.
| Operating system | Status | Covered kernels |
|---|---|---|
| Debian 12 | Planned | — |
| Debian 13 | Released |
15 kernels
|
| Oracle Linux 9 UEK 7 | Planned | — |