#VU21716 Double Free in Linux kernel - CVE-2017-18595
Published: October 11, 2019
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to escalate privileges in the system.
The vulnerability exists due to a boundary error within the allocate_trace_buffer() function in the kernel/trace/trace.c. A local user can run a specially crafted application to trigger a double free error and execute arbitrary code on the target system with elevated privileges.