Description
In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on ublk char device for filling request buffer, and unprivileged device can't be trusted. So don't allow user copy for unprivileged device.
References (3)
Core 3
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
10.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (12)
linux/Kernel
6.5.0 - 6.6.58linux
linux/Kernel
6.7.0 - 6.11.5linux
Linux/Linux
< 6.5
Linux/Linux
1172d5b8beca6b899deb9f7f2850e7e47ec16198 - 42aafd8b48adac1c3b20fe5892b1b91b80c1a1e6
Linux/Linux
1172d5b8beca6b899deb9f7f2850e7e47ec16198 - 6414ab5c9c9c068eca6dc4fd3a036bc4b83164dc
Linux/Linux
1172d5b8beca6b899deb9f7f2850e7e47ec16198 - 8f3d5686a2409877c5e8e2540774d24ed2b4a4ce
Linux/Linux
6.11.5 - 6.11.*
Linux/Linux
6.12
Linux/Linux
6.5
Linux/Linux
6.6.58 - 6.6.*
... and 2 more
Published
Oct 29, 2024
Tracked Since
Feb 18, 2026