In construct_transaction_from_cmd of lwis_ioctl.c, there...
High severity
Unreviewed
Published
Jan 3, 2025
to the GitHub Advisory Database
•
Updated Jan 4, 2025
Description
Published by the National Vulnerability Database
Jan 3, 2025
Published to the GitHub Advisory Database
Jan 3, 2025
Last updated
Jan 4, 2025
In construct_transaction_from_cmd of lwis_ioctl.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
References