CVEbaza.plSłownik CWECWE-368
Common Weakness Enumeration

CWE-368

Context Switching Race Condition

Kategoria: BaseCVE: 6
Opis

Produkt wykonuje serię nieatomowych działań w celu przełączenia między kontekstami przekraczającymi granice uprawnień lub innych granic bezpieczeństwa, jednak warunek wyścigu umożliwia atakującemu modyfikację lub fałszowanie zachowania produktu podczas przełączania. Luka ta pozwala na manipulowanie procesem przejścia między różnymi poziomami uprawnień.

Description (EN)

A product performs a series of non-atomic actions to switch between contexts that cross privilege or other security boundaries, but a race condition allows an attacker to modify or misrepresent the product's behavior during the switch.

Podatności CVE z CWE-368 (6)
9.8
CVSS
CRITICAL
CVE-2022-21806

W oprogramowaniu Anker Eufy Homebase 2 (wersja 2.1.8.5h) wykryto podatność typu use-after-free w komponencie mips_collector appsrv_server. Luka umożliwia zdalne wykonanie kodu bez uwierzytelnienia, co czyni ją krytycznym zagrożeniem dla bezpieczeństwa urządzenia.

pub. 2022-06-17
9.0
CVSS
CRITICAL
CVE-2021-21941

Podatność typu use-after-free w funkcji pushMuxer CreatePushThread urządzenia Anker Eufy Homebase 2 pozwala zdalnemu atakującemu na wykonanie dowolnego kodu bez uwierzytelnienia. Wysoki wynik CVSS (9.0) oraz zdalna exploitowalność czynią ją poważnym zagrożeniem dla bezpieczeństwa sieci domowych.

pub. 2021-10-12
8.1
CVSS
HIGH
CVE-2021-32025

An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX OS for Medical version 2.0.0 could allow an attacker to potentially access data, modify behavior, or permanently crash the system.

pub. 2022-03-10
7.0
CVSS
HIGH
CVE-2026-3006

Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software.

pub. 2026-04-27
7.0
CVSS
HIGH
CVE-2024-34731

In multiple functions of TranscodingResourcePolicy.cpp, there is a possible memory corruption due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

pub. 2024-08-15
6.5
CVSS
MEDIUM
CVE-2020-8834

KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to panic. There were two commits that, according to the reporter, introduced the vulnerability: f024ee098476 ("KVM: PPC: Book3S HV: Pull out TM state save/restore into separate procedures") 87a11bb6a7f7 ("KVM: PPC: Book3S HV: Work around XER[SO] bug in fake suspend mode") The former landed in 4.8, the latter in 4.17. This was fixed without realizing the impact in 4.18 with the following three commits, though it's believed the first is the only strictly necessary commit: 6f597c6b63b6 ("KVM: PPC: Book3S PR: Add guest MSR parameter for kvmppc_save_tm()/kvmppc_restore_tm()") 7b0e827c6970 ("KVM: PPC: Book3S HV: Factor fake-suspend handling out of kvmppc_save/restore_tm") 009c872a8bc4 ("KVM: PPC: Book3S PR: Move kvmppc_save_tm/kvmppc_restore_tm to separate file")

pub. 2020-04-09
Informacje
ID: CWE-368
Typ: Base
Podatności: 6
MITRE CWE ↗
← Słownik CWE