In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb.c: fix UAF of vma in hugetlb fault pathway Syzbot reports a UAF in hugetlb_fault(). This happens because vmf_anon_prepare() could drop the per-VMA lock and allow the current VMA to be freed before hugetlb_vma_unlock_read() is called. We can fix this by using a modified version of vmf_anon_prepare() that doesn't release the VMA lock on failure, and then release it ourselves after hugetlb_vma_unlock_read().
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 4.0.6 |
| Linux | Linux | 5.0 |
| Linux | Linux | Java SE: 6u171 |
| Linux | Linux | 9.0.1; Java SE Embedded: 8u151 |