kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
{ "binaries": [ { "binary_version": "5.14.0-1022.24", "binary_name": "linux-buildinfo-5.14.0-1022-oem" }, { "binary_version": "5.14.0-1022.24", "binary_name": "linux-headers-5.14.0-1022-oem" }, { "binary_version": "5.14.0-1022.24", "binary_name": "linux-image-unsigned-5.14.0-1022-oem" }, { "binary_version": "5.14.0-1022.24", "binary_name": "linux-image-unsigned-5.14.0-1022-oem-dbgsym" }, { "binary_version": "5.14.0-1022.24", "binary_name": "linux-modules-5.14.0-1022-oem" }, { "binary_version": "5.14.0-1022.24", "binary_name": "linux-oem-5.14-headers-5.14.0-1022" }, { "binary_version": "5.14.0-1022.24", "binary_name": "linux-oem-5.14-tools-5.14.0-1022" }, { "binary_version": "5.14.0-1022.24", "binary_name": "linux-oem-5.14-tools-host" }, { "binary_version": "5.14.0-1022.24", "binary_name": "linux-tools-5.14.0-1022-oem" } ], "availability": "No subscription required" }