CyberRota Analysis
AI-GeneratedThe vulnerability arises from a race condition in the kernel's handling of knotes during the fork operation, which can lead to a use-after-free condition. This flaw allows an unprivileged local user to exploit the kernel's active list, potentially enabling privilege escalation. Organizations using affected kernel versions should prioritize patching to mitigate the risk of unauthorized access and system compromise.
Original NVD Description
While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the copy was complete. The copy routine did not account for this and could enqueue the new knote a second time, corrupting the active list. In addition, the copy routine did not hold the appropriate locks while reading knote state, allowing further races. An unprivileged local user can trigger a use-after-free in the kernel, potentially leading to privilege escalation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)