kernel: use-after-free in kernel midi subsystem
Published Dec 11, 2020
7.8
HIGHCVSS 3.1
EPSS 1.67%
Description
A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of execution to change and possibly allow for memory corruption or privilege escalation. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected products
- Vendor n/a Product Kernel Defaultunknown
Affected
- kernel 5.7-rc6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Kernel | unknown | Affected
|
Configuration 1
- < 4.4.224
- ≥ 4.5 · < 4.9.224
- ≥ 4.10 · < 4.14.181
- ≥ 4.15 · < 4.19.124
- ≥ 4.20 · < 5.4.42
- ≥ 5.5 · < 5.6.14
Configuration 2
- 4.4
- 4.5
- 4.6
- 7.0
- 8.0
- 2.0
Configuration 3
- n/a
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-305.el8
Fixed · RHSA-2021:1578
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-305.rt7.72.el8
Fixed · RHSA-2021:1739
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Will not fix
Red Hat Enterprise MRG 2
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-305.el8 | Fixed | RHSA-2021:1578 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-305.rt7.72.el8 | Fixed | RHSA-2021:1739 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Will not fix | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
As the midi module will be auto-loaded when required, its use can be disabled by preventing the module from loading with the following instructions: # echo "install snd-rawmidi /bin/true" >> /etc/modprobe.d/disable-snd-rawmidi.conf The system will need to be restarted if the snd-rawmidi modules are loaded. In most circumstances, the CIFS kernel modules will be unable to be unloaded while any midi / sound devices are active and the protocol is in use. If the system requires this module to work correctly, this mitigation may not be suitable. If you need further assistance, see KCS article https://access.redhat.com/solutions/41278 or contact Red Hat Global Support Services.
References (8)
- http://www.openwall.com/lists/oss-security/2020/12/03/1 mailing-listx_refsource_MLISTMailing List
- https://access.redhat.com/security/cve/CVE-2020-27786 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1900933 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-20288 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c1f6e3c818dd734c30f6a7eeebf232ba2cf3181d x_refsource_MISCPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-27786
- https://security.netapp.com/advisory/ntap-20210122-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-27786
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2020/12/03/1 | mailing-listx_refsource_MLISTMailing List | |
| https://access.redhat.com/security/cve/CVE-2020-27786 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1900933 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-20288 | Advisory | |
| https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c1f6e3c818dd734c30f6a7eeebf232ba2cf3181d | x_refsource_MISCPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-27786 | ||
| https://security.netapp.com/advisory/ntap-20210122-0002/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-27786 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data