CVE-2020-36385

Related Vulnerabilities: CVE-2020-36385  

An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.

Description

The MITRE CVE dictionary describes this issue as:

An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.

Additional Information

  • Bugzilla 1974319: CVE-2020-36385 kernel: use-after-free in drivers/infiniband/core/ucma.c ecause the ctx is reached via the ctx_list
  • CWE-416: Use After Free
  • FAQ: Frequently asked questions about CVE-2020-36385