In the Linux kernel, the following vulnerability has been resolved: riscv: misaligned: Restrict user access to kernel memory raw_copy_{to,from}_user() do not call access_ok(), so this code allowed userspace to access any virtual memory address.
This Cyber News was published on www.tenable.com. Publication date: Wed, 18 Sep 2024 21:11:02 +0000