looprwiter in fs/iouring.c in the Linux kernel 5.10 through 5.14.6 allows local users to gain privileges by using IORINGOPPROVIDEBUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41073.json"
[
{
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@16c8d2df7ec0eed31b7d3b61cb13206a7fb930cc",
"digest": {
"line_hashes": [
"316601498373019185530402480592852461240",
"334068663808384384470115602288501871851",
"59368718648727489287442766150615528934",
"169316838539460318129556301584396204405",
"224463564704914729872761549467519827296",
"63717184302129202837388413702734619953",
"213858589222833138040480060887104103382",
"183887848698582677381710947351798662449",
"121915552438693331285936965844853594238",
"87378863576248367635176297446893295745"
],
"threshold": 0.9
},
"id": "CVE-2021-41073-90816cea",
"deprecated": false,
"target": {
"file": "fs/io_uring.c"
}
},
{
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git@16c8d2df7ec0eed31b7d3b61cb13206a7fb930cc",
"digest": {
"function_hash": "36269753335818830633146718686260474855",
"length": 901.0
},
"id": "CVE-2021-41073-d248b1db",
"deprecated": false,
"target": {
"file": "fs/io_uring.c",
"function": "loop_rw_iter"
}
}
]