CVE-2020-29661: Use After Free
A locking issue was discovered in the tty subsystem of the Linux kernel in drivers/tty/ttyjobctrl.c which could allow an attacker with a local account to possibly corrupt memory or escalate privileges.
Reference and upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=54ffccbf053b5b6ca4f6e45094b942fab92a25fc
Other sources
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/ttyjobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
A locking vulnerability was found in the tty subsystem of the Linux kernel in drivers/tty/ttyjobctrl.c. This flaw allows a local attacker to possibly corrupt memory or escalate privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected Software
Remediation
Information
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-29661?
CVE-2020-29661 is classified as a high severity vulnerability that could allow an attacker to corrupt memory or escalate privileges.
How can I fix CVE-2020-29661?
To mitigate CVE-2020-29661, update your Linux kernel to the patched versions provided by your Linux distribution.
What versions of the Linux kernel are affected by CVE-2020-29661?
CVE-2020-29661 affects multiple versions of the Linux kernel, particularly those prior to the patched releases mentioned in your distribution's advisory.
Is CVE-2020-29661 exploitable remotely?
CVE-2020-29661 is not considered remotely exploitable; it requires local access to the affected system.
Are there any specific distributions affected by CVE-2020-29661?
Yes, CVE-2020-29661 impacts various distributions including Red Hat, Fedora, and Debian.