7.2
CVSSv2

CVE-2020-29661

Published: 09/12/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 642
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

A locking issue exists in the tty subsystem of the Linux kernel up to and including 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel

fedoraproject fedora 32

fedoraproject fedora 33

debian debian linux 9.0

debian debian linux 10.0

netapp active iq unified manager -

broadcom fabric operating system -

netapp solidfire_baseboard_management_controller_firmware -

netapp h410c_firmware -

netapp a700s_firmware -

netapp 8300_firmware -

netapp 8700_firmware -

netapp a400_firmware -

oracle tekelec platform distribution

Vendor Advisories

Synopsis Important: kernel-alt security update Type/Severity Security Advisory: Important Topic An update for kernel-alt is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base ...
Synopsis Important: kernel-rt security and bug fix update Type/Severity Security Advisory: Important Topic An update for kernel-rt is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (C ...
Synopsis Important: kernel security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for kernel is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks CVE-2020-27815 A flaw was reported in the JFS filesystem code allowing a local attacker with the ability to set extended attributes to cause a denial of service CVE-2020-27825 Adam pi3 Z ...
In the Linux kernel 5021, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutexc This is related to mutex_can_spin_on_owner in kernel/locking/mutexc, __btrfs_qgroup_free_meta in fs/btrfs/qgroupc, and btrfs_insert_delayed_ ...
A locking issue was discovered in the tty subsystem of the Linux kernel through 5913 drivers/tty/tty_jobctrlc allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b ...
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5913 drivers/tty/tty_ioc and drivers/tty/tty_jobctrlc may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24 (CVE-2020-29660) A locking vulnerability was found in the tty subsystem of the Linux kernel in drivers/tty/tty_jobctrlc ...
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5913 drivers/tty/tty_ioc and drivers/tty/tty_jobctrlc may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24 (CVE-2020-29660) A locking vulnerability was found in the tty subsystem of the Linux kernel in drivers/tty/tty_jobctrlc ...
A flaw was found in the JFS filesystem code This flaw allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability (CVE-2020-27815) A flaw was found in the Linu ...
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5913 drivers/tty/tty_ioc and drivers/tty/tty_jobctrlc may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24 (CVE-2020-29660) A locking vulnerability was found in the tty subsystem of the Linux kernel in drivers/tty/tty_jobctrlc ...
In the Linux kernel 5021, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutexc This is related to mutex_can_spin_on_owner in kernel/locking/mutexc, __btrfs_qgroup_free_meta in fs/btrfs/qgroupc, and btrfs_insert_delayed_ ...
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5913 drivers/tty/tty_ioc and drivers/tty/tty_jobctrlc may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24 (CVE-2020-29660) A locking vulnerability was found in the tty subsystem of the Linux kernel in drivers/tty/tty_jobctrlc ...

Exploits

Linux suffers from broken locking in TIOCSPGRP that can lead to a corrupted refcount ...