CVE-2020-29660: Use After Free
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/ttyio.c and drivers/tty/ttyjobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.
Other sources
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/ttyio.c and drivers/tty/ttyjobctrl.c may allow a read-after-free attack against TIOCGSID.
Reference and upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c8bcd9c5be24fb9e6132e97da5a35e55a83e36b9
— Red Hat
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel. A local user could use this flaw to read numerical value from memory after free.
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-29660?
CVE-2020-29660 is considered a medium-severity vulnerability that can lead to read-after-free attacks in the Linux kernel.
How do I fix CVE-2020-29660?
To fix CVE-2020-29660, upgrade to kernel versions 0:4.18.0-348.rt7.130.el8 or 0:4.18.0-348.el8 or later.
Which Linux kernel versions are affected by CVE-2020-29660?
CVE-2020-29660 affects Linux kernel versions through 5.9.13.
Are there any specific distributions impacted by CVE-2020-29660?
Yes, CVE-2020-29660 affects Red Hat, Debian, and various Fedora distributions.
What component of the Linux kernel is vulnerable in CVE-2020-29660?
CVE-2020-29660 involves a locking inconsistency issue in the tty subsystem of the Linux kernel.