CVE-2024-46792

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/09/2024
Last modified:
20/09/2024

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> riscv: misaligned: Restrict user access to kernel memory<br /> <br /> raw_copy_{to,from}_user() do not call access_ok(), so this code allowed<br /> userspace to access any virtual memory address.

Impact