ZeroHour

CVE-2023-1077

CVSS 3.1
7.0 high
EPSS
<1%p20
Published
()
Modified
Description

In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,which would then be used as a type confused sched_rt_entity,causing memory corruption.

Vendors
linuxdebiannetapp
Products
linux kernel, debian linux, a700s firmware, 8300 firmware, 8700 firmware, a400 firmware, c400 firmware, h300s firmware, h500s firmware, h700s firmware, h410s firmware, h410c firmware
Weakness
CWE-843
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.