usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference. References: Upstream commit:

Created kernel tracking bugs for this issue: Affects: fedora-all [

This was fixed for Fedora with the 5.6.8 stable kernel updates.

Source link

You must be logged in to post a comment.