It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.
The product uses a reference count to manage a resource, but it does not update or incorrectly updates the reference count.
Link | Tags |
---|---|
https://ubuntu.com/security/CVE-2020-11935 | vendor advisory |
https://bugs.launchpad.net/bugs/1873074 | vendor advisory issue tracking |