Arbitrary Code Execution via Use After Free in DevmemIntMapPMR

Arbitrary Code Execution via Use After Free in DevmemIntMapPMR

CVE-2023-21164 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In DevmemIntMapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

Learn more about our Cis Benchmark Audit For Server Software.