hanwckf / rt-n56u

Padavan
3.28k stars 3.68k forks source link

Security Vulnerability - Action Required: Use After Free vulnerability may in your project #802

Open Crispy-fried-chicken opened 2 months ago

Crispy-fried-chicken commented 2 months ago

Hi, we have detected that your project may be vulnerable to Use After Free in the function of ene_remove in the file of trunk/linux-3.4.x/drivers/media/rc/ene_ir.c . It shares similarities to a recent CVE disclosure CVE-2023-1118 in the linux.

The source vulnerability information is as follows:

Vulnerability Detail: CVE Identifier: CVE-2023-1118 Description: A flaw use after free in the Linux kernel integrated infrared receiver/transceiver driver was found in the way user detaching rc device. A local user could use this flaw to crash the system or potentially escalate their privileges on the system. Reference: https://nvd.nist.gov/vuln/detail/CVE-2023-1118 Patch: https://github.com/torvalds/linux/commit/29b0589a865b6f66d141d79b2dd1373e4e50fe17

Would you help to check if this bug is true? If it's true, I'd like to open a PR for that if necessary. Thank you for your effort and patience!