Race condition in Chrome OS - #VU77118

 

Race condition in Chrome OS - #VU77118

Published: June 9, 2023


Vulnerability identifier: #VU77118
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a race condition within the amdgpu_ttm_tt_get_user_pages() function. A local application can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

Chrome OS

Remediation

Install updates from vendor's website.

Chrome OS - update to 114.0.5735.119

External References

Related Security Bulletins