Overview
About vulnerability
In the Linux kernel, the following vulnerability has been resolved:
debugfs: Fix lockdown check for mmap_prepare
Commit 651fdda8406d (“relay: update relay to use mmap_prepare”)
changed the mmap file operation to mmap_prepare for relayfs, but
the lockdown check in debugfs was not updated accordingly.
This prevents debugfs from being locked down when the kernel is in
integrity mode if a file uses mmap_prepare but not mmap.
Since the conversion to mmap_prepare across the kernel is not yet
complete, update the lockdown check to look for both mmap and
mmap_prepare to ensure comprehensive coverage.
Details
- Affected product:
- Debian 10 ELS , Debian 11 ELS
- Affected packages:
- linux @ 5.10.259 (+1 more)