Summary
In the Linux kernel's XFRM ESP-in-TCP subsystem, unsafe in-place cryptographic processing allows a low-privileged local attacker to write arbitrary bytes into the page cache of read-only files, including sensitive system files. An attacker ca...