A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this issue is some unknown functionality. The manipulation leads to race condition. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-261596.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://vuldb.com/?id.261596 | vdb entry |
https://vuldb.com/?ctiid.261596 | signature permissions required |
https://vuldb.com/?submit.312410 | third party advisory |
https://github.com/COVESA/vsomeip/issues/663 | issue tracking |
https://github.com/COVESA/vsomeip/files/14904610/details.zip | exploit |