CVE-2020-12826

Description

A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.068

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Linux kernel (USN-4391-1) linux-image-aws_4.4.0.1109.113_amd64.debLinux
Linux kernel (USN-4391-1) linux-image-kvm_4.4.0.1075.73_amd64.debLinux
Linux kernel (USN-4391-1) linux-image-generic_4.4.0.184.190_i386.debLinux
Linux kernel (USN-4391-1) linux-image-generic_4.4.0.184.190_amd64.debLinux
Linux kernel (USN-4391-1) linux-image-virtual_4.4.0.184.190_i386.debLinux
Linux kernel (USN-4391-1) linux-image-virtual_4.4.0.184.190_amd64.debLinux
Linux kernel (USN-4391-1) linux-image-lowlatency_4.4.0.184.190_i386.debLinux
Linux kernel (USN-4391-1) linux-image-lowlatency_4.4.0.184.190_amd64.debLinux
Linux kernel (USN-4391-1) linux-image-4.4.0-1075-kvm_4.4.0-1075.82_amd64.debLinux
Linux kernel (USN-4391-1) linux-image-4.4.0-1109-aws_4.4.0-1109.120_amd64.debLinux
Linux kernel (USN-4391-1) linux-image-4.4.0-184-generic_4.4.0-184.214_i386.debLinux
Linux kernel (USN-4391-1) linux-image-4.4.0-184-generic_4.4.0-184.214_amd64.debLinux
Linux kernel (USN-4391-1) linux-image-4.4.0-184-lowlatency_4.4.0-184.214_i386.debLinux
Linux kernel (USN-4391-1) linux-image-4.4.0-184-lowlatency_4.4.0-184.214_amd64.debLinux
kernel Security Update (ALAS-2020-1440) kernel-livepatch-4.14.177-139.253-1.0-0.amzn2.x86_64.rpmLinux
Integer Overflow or Wraparound Vulnerability (CVE-2020-12826)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234