CVE-2020-10690

Description

There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition as the process wakes up to terminate and clean all attached files. The system crashes due to the cdev structure being invalid (as already freed) which is pointed to by the inode.

Risk Information

Base Score
6.4
MODERATE
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.126

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
SUSE-SU-2020:14393-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-108.114.1.i586.rpmLinux
SUSE-SU-2020:14393-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-default-extra-3.0.101-108.114.1.x86_64.rpmLinux
SUSE-SU-2020:14393-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-pae-extra-3.0.101-108.114.1.i586.rpmLinux
SUSE-SU-2020:14393-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-trace-extra-3.0.101-108.114.1.x86_64.rpmLinux
SUSE-SU-2020:14393-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-108.114.1.i586.rpmLinux
SUSE-SU-2020:14393-1(SUSE Linux Enterprise Server 11-EXTRA ) kernel-xen-extra-3.0.101-108.114.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-base-debuginfo-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debuginfo-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-debugsource-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-azure-devel-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-devel-azure-4.12.14-16.16.1.noarch.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-source-azure-4.12.14-16.16.1.noarch.rpmLinux
SUSE-SU-2020:1587-1(SUSE Linux Enterprise Server 12-SP5 ) kernel-syms-azure-4.12.14-16.16.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-base-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-base-debuginfo-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-debuginfo-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-debugsource-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-azure-devel-4.12.14-6.43.1.x86_64.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-devel-azure-4.12.14-6.43.1.noarch.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-source-azure-4.12.14-6.43.1.noarch.rpmLinux
SUSE-SU-2020:1603-1(SUSE Linux Enterprise Server 12-SP4 ) kernel-syms-azure-4.12.14-6.43.1.x86_64.rpmLinux
Linux kernel (USN-4419-1) linux-image-aws_4.4.0.1110.114_amd64.debLinux
Linux kernel (USN-4419-1) linux-image-kvm_4.4.0.1076.74_amd64.debLinux
Linux kernel (USN-4419-1) linux-image-generic_4.4.0.185.191_i386.debLinux
Linux kernel (USN-4419-1) linux-image-generic_4.4.0.185.191_amd64.debLinux
Linux kernel (USN-4419-1) linux-image-virtual_4.4.0.185.191_i386.debLinux
Linux kernel (USN-4419-1) linux-image-virtual_4.4.0.185.191_amd64.debLinux
Linux kernel (USN-4419-1) linux-image-lowlatency_4.4.0.185.191_i386.debLinux
Linux kernel (USN-4419-1) linux-image-lowlatency_4.4.0.185.191_amd64.debLinux
Linux kernel (USN-4419-1) linux-image-4.4.0-1076-kvm_4.4.0-1076.83_amd64.debLinux
Linux kernel (USN-4419-1) linux-image-4.4.0-1110-aws_4.4.0-1110.121_amd64.debLinux
Linux kernel (USN-4419-1) linux-image-4.4.0-185-generic_4.4.0-185.215_i386.debLinux
Linux kernel (USN-4419-1) linux-image-4.4.0-185-generic_4.4.0-185.215_amd64.debLinux
Linux kernel (USN-4419-1) linux-image-4.4.0-185-lowlatency_4.4.0-185.215_i386.debLinux
Linux kernel (USN-4419-1) linux-image-4.4.0-185-lowlatency_4.4.0-185.215_amd64.debLinux
Kernel-uek update (ELSA-2022-9969) kernel-uek-4.1.12-124.68.3.el7uek.x86_64.rpmLinux
Kernel-uek-debug update (ELSA-2022-9969) kernel-uek-debug-4.1.12-124.68.3.el7uek.x86_64.rpmLinux
Kernel-uek-debug-devel update (ELSA-2022-9969) kernel-uek-debug-devel-4.1.12-124.68.3.el7uek.x86_64.rpmLinux
Kernel-uek-devel update (ELSA-2022-9969) kernel-uek-devel-4.1.12-124.68.3.el7uek.x86_64.rpmLinux
Kernel-uek-doc update (ELSA-2022-9969) kernel-uek-doc-4.1.12-124.68.3.el7uek.noarch.rpmLinux
Kernel-uek-firmware update (ELSA-2022-9969) kernel-uek-firmware-4.1.12-124.68.3.el7uek.noarch.rpmLinux
Use After Free Vulnerability (CVE-2020-10690)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234