Use-after-free in Linux kernel - CVE-2014-5332
Published: February 6, 2015 / Updated: August 9, 2020
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when processing a crafted NVMAP_IOC_CREATE IOCTL call, which triggers a use-after-free error, as demonstrated by using a race condition to escape the Chrome sandbox. A local users can gain privileges.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.