AppArmor Credential Fix Prevents In-Hook Use-After-Free Risk

DedicatedLinux

A Linux security hook should be able to check a task without invalidating the identity data that surrounding kernel code is still using. AppArmor broke that expectation when a policy update made the task’s current label stale: code inside widely used hooks could replace the task’s credentials before the caller had finished with them.LinuxSecurity – Security ArticlesRead More