An issue exists in GNU Hurd prior to 0.9 20210404-9. libports accepts fake notification messages from any client on any port, which can lead to port use-after-free. This can be exploited for local privilege escalation to get full root access.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gnu hurd |