Linux Kernel Improper Input Validation Vulnerability
Linux · Kernel
Date added (CISA)
2022-09-15
Remediation due
2022-10-06
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an application to read and write kernel memory which could lead to privilege escalation.