CVE Published: 29/10/2024 |
CVE Updated: 19/11/2024 |
CVE Year: 2024 Source: Linux |
Vendor: Linux |
Product: Linux Status : PUBLISHED
CVE-2024-50080 Description
In the Linux kernel, the following vulnerability has been resolved:
ublk: don\'t allow user copy for unprivileged device
UBLK_F_USER_COPY requires userspace to call write() on ublk char
device for filling request buffer, and unprivileged device can\'t
be trusted.
So don\'t allow user copy for unprivileged device.