A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly can lead to a situation where a fork event will be removed from an already freed list of events with userfaultfdctxput().
{ "binaries": [ { "binary_version": "4.13.0-1005.7", "binary_name": "linux-azure-cloud-tools-4.13.0-1005" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-azure-cloud-tools-4.13.0-1005-dbgsym" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-azure-headers-4.13.0-1005" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-azure-tools-4.13.0-1005" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-azure-tools-4.13.0-1005-dbgsym" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-cloud-tools-4.13.0-1005-azure" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-headers-4.13.0-1005-azure" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-image-4.13.0-1005-azure" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-image-4.13.0-1005-azure-dbgsym" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-image-extra-4.13.0-1005-azure" }, { "binary_version": "4.13.0-1005.7", "binary_name": "linux-tools-4.13.0-1005-azure" } ], "availability": "No subscription required" }