kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-5.14.0-1022-oem", "binary_version": "5.14.0-1022.24" }, { "binary_name": "linux-headers-5.14.0-1022-oem", "binary_version": "5.14.0-1022.24" }, { "binary_name": "linux-image-unsigned-5.14.0-1022-oem", "binary_version": "5.14.0-1022.24" }, { "binary_name": "linux-image-unsigned-5.14.0-1022-oem-dbgsym", "binary_version": "5.14.0-1022.24" }, { "binary_name": "linux-modules-5.14.0-1022-oem", "binary_version": "5.14.0-1022.24" }, { "binary_name": "linux-oem-5.14-headers-5.14.0-1022", "binary_version": "5.14.0-1022.24" }, { "binary_name": "linux-oem-5.14-tools-5.14.0-1022", "binary_version": "5.14.0-1022.24" }, { "binary_name": "linux-oem-5.14-tools-host", "binary_version": "5.14.0-1022.24" }, { "binary_name": "linux-tools-5.14.0-1022-oem", "binary_version": "5.14.0-1022.24" } ] }