kernel: locking inconsistency in drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c can lead to a read-after-free
Published Dec 9, 2020
4.4
MEDIUMCVSS 3.1
EPSS 0.47%
Description
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.
Affected products
No data.
Configuration 1
- ≤ 5.9.13
Configuration 2
- 32
- 33
Configuration 3
- 9.0
- 10.0
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
Running on/with
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
No data.
Red Hat Enterprise Linux 8
kernel-0:4.18.0-348.el8
Fixed · RHSA-2021:4356
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-348.rt7.130.el8
Fixed · RHSA-2021:4140
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Fix deferred
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 7
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-348.el8 | Fixed | RHSA-2021:4356 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-348.rt7.130.el8 | Fixed | RHSA-2021:4140 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is rated as having Low impact (Red Hat Enterprise Linux 7) because of the need to have CAP_SYS_TTY_CONFIG privileges. This flaw is rated as having Moderate (Red Hat Enterprise Linux 8) impact because of the need to have CAP_SYS_TTY_CONFIG privileges. Red Hat Enterprise Linux 8 enabled unprivileged user/network namespaces by default which can be used to exercise this vulnerability.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (14)
- http://packetstormsecurity.com/files/164950/Kernel-Live-Patch-Security-Notice-LSN-0082-1.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2020/12/10/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-29660 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1906522 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-22018 Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c8bcd9c5be24fb9e6132e97da5a35e55a83e36b9 x_refsource_MISCExploitPatchVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00018.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00010.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BOB25SU6XUL4TNP7KB63WNZSYTIYFDPP/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZ7OAKAEFAXQRGBZK4LYUWINCD3D2XCL/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-29660
- https://security.netapp.com/advisory/ntap-20210122-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-29660
- https://www.debian.org/security/2021/dsa-4843 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.