Use-after-free in Linux kernel - CVE-2019-18814
Published: January 21, 2020
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when "aa_label_parse()" fails in "aa_audit_rule_init()" in security/apparmor/audit.c. A local user can execute arbitrary code on the target system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.