CVE-2020-35508: Race Condition
A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.
Other sources
A flaw was found in the Red Hat Linux kernel. It's possible to send arbitrary signals to a privileged (suidroot) parent process.
— Red Hat
Affected Software
Remediation
Information
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-35508?
CVE-2020-35508 has a medium severity level due to the potential for local attacks to bypass checks for sending signals to privileged processes.
How do I fix CVE-2020-35508?
To fix CVE-2020-35508, update the affected packages to the specified patched versions provided by your distribution.
What systems are affected by CVE-2020-35508?
CVE-2020-35508 affects various versions of the Linux kernel, specifically Red Hat kernel-rt and Debian Linux packages among others.
What exploit capabilities does CVE-2020-35508 provide to attackers?
CVE-2020-35508 allows local attackers to exploit race conditions to send signals to privileged processes, potentially leading to unauthorized actions.
Is CVE-2020-35508 specific to any Linux distributions?
While CVE-2020-35508 impacts the Linux kernel, it is particularly relevant to Red Hat and Debian distributions due to the affected versions listed.