Problem Description:
The ELF core dump code counted the number of dumpable VM map
entries, allocated a buffer for the corresponding program headers,
then iterated over the map a second time to populate them. A process
sharing the address space via rfork(2) can mutate the map between
the two passes, causing the second pass to write program headers
past the end of the buffer.
Impact:
An unprivileged local user sharing an address space with a
process that dumps core can trigger an out-of-bounds write on the
kernel heap, potentially leading to privilege escalation.