A NULL pointer dereference was found in iofilebitmapget in iouring/filetable.c in the iouring sub-component in the Linux Kernel. When fixed files are unregistered, some context information (filealloc{start,end} and allochint) is not cleared. A subsequent request that has auto index selection enabled via IORINGFILEINDEX_ALLOC can cause a NULL pointer dereference. An unprivileged user can use the flaw to cause a system crash.
{ "binaries": [ { "binary_version": "6.1.0-1009.9", "binary_name": "linux-buildinfo-6.1.0-1009-oem" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-headers-6.1.0-1009-oem" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-image-unsigned-6.1.0-1009-oem" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-image-unsigned-6.1.0-1009-oem-dbgsym" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-modules-6.1.0-1009-oem" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-modules-ipu6-6.1.0-1009-oem" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-modules-ivsc-6.1.0-1009-oem" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-oem-6.1-headers-6.1.0-1009" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-oem-6.1-tools-6.1.0-1009" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-oem-6.1-tools-host" }, { "binary_version": "6.1.0-1009.9", "binary_name": "linux-tools-6.1.0-1009-oem" } ], "availability": "No subscription required" }