kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
Product | Vendor | Version |
---|---|---|
n/a | n/a | < 3d2f78f08cd8388035ac375e731ec1ac1b79b09d |