Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix potential UAF in aa_replace_profiles
The function aa_replace_profiles was accessing udata->size after calling aa_put_loaddata(udata), causing a potential UAF.
Fixed this by saving the size to a local variable before dropping the reference.
Details
- Affected product:
- Debian 10 ELS , Debian 11 ELS , Ubuntu 18.04 ELS , Ubuntu 20.04 ELS
- Affected packages:
- linux @ 5.4.0 (+3 more)