A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2021/05/25/1 | mailing list third party advisory exploit |
http://www.openwall.com/lists/oss-security/2021/06/01/2 | exploit mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1964139 | third party advisory issue tracking |
https://www.openwall.com/lists/oss-security/2021/05/25/1 | mailing list third party advisory exploit |
https://lists.debian.org/debian-lts-announce/2021/06/msg00020.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2021/06/msg00019.html | third party advisory mailing list |