CVE-2020-15710: Potential double-free in pulseaudio

Published Nov 19, 2020
·
Updated

Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail condition in src/modules/bluetooth/module-bluez5-device.c and src/modules/bluetooth/module-bluez5-device.c. Fixed in 1:8.0-0ubuntu3.14.

Affected Software

17 affected components
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu1
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu2
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.1
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.2
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.3
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.4
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.5
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.6
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.7
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.8
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.9
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.10
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.11
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu3.12
Pulseaudio Project Pulseaudio=1\-8.0-0ubuntu4
Canonical Ubuntu Linux=16.04

Event History

Nov 19, 2020
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2020-15710?

CVE-2020-15710 is considered to have a medium severity due to potential memory leaks and crashing.

2

How do I fix CVE-2020-15710?

To fix CVE-2020-15710, update PulseAudio to the latest version that resolves the double free issue.

3

What systems are affected by CVE-2020-15710?

CVE-2020-15710 affects PulseAudio versions 1:8.0-0ubuntu1 to 1:8.0-0ubuntu4.

4

Can CVE-2020-15710 be exploited remotely?

No, CVE-2020-15710 requires local access to exploit the vulnerability.

5

What are the consequences of CVE-2020-15710?

The consequences of CVE-2020-15710 include potential memory leaks or application crashes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203