A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly can lead to a situation where a fork event will be removed from an already freed list of events with userfaultfdctxput().
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-azure-cloud-tools-4.13.0-1005", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-azure-cloud-tools-4.13.0-1005-dbgsym", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-azure-headers-4.13.0-1005", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-azure-tools-4.13.0-1005", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-azure-tools-4.13.0-1005-dbgsym", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-cloud-tools-4.13.0-1005-azure", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-headers-4.13.0-1005-azure", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-image-4.13.0-1005-azure", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-image-4.13.0-1005-azure-dbgsym", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-image-extra-4.13.0-1005-azure", "binary_version": "4.13.0-1005.7" }, { "binary_name": "linux-tools-4.13.0-1005-azure", "binary_version": "4.13.0-1005.7" } ] }