Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-27820

Опубликовано: 03 нояб. 2020
Источник: redhat
CVSS3: 4.1
EPSS Низкий

Описание

A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).

Отчет

This flaw is rated as having a Low impact because the issue can only be triggered by an privileged local user (or user with physical access) as the issue only happens during unbinding the driver or removing the device.

Меры по смягчению последствий

To mitigate this issue, prevent the module nouveau from being loaded. Please see https://access.redhat.com/solutions/41278 for information on how to blacklist a kernel module to prevent it from loading automatically.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelFix deferred
Red Hat Enterprise Linux 7kernel-altFix deferred
Red Hat Enterprise Linux 7kernel-rtFix deferred
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise MRG 2kernelOut of support scope
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2022:197510.05.2022
Red Hat Enterprise Linux 8kernelFixedRHSA-2022:198810.05.2022

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1901726kernel: use-after-free in nouveau kernel module

EPSS

Процентиль: 3%
0.00019
Низкий

4.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 3 лет назад

A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).

CVSS3: 4.7
nvd
больше 3 лет назад

A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).

CVSS3: 4.7
debian
больше 3 лет назад

A vulnerability was found in Linux kernel, where a use-after-frees in ...

CVSS3: 4.7
github
около 3 лет назад

A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).

CVSS3: 4.7
fstec
больше 3 лет назад

Уязвимость функции postclose() ядра операционной системы Linux, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 3%
0.00019
Низкий

4.1 Medium

CVSS3

Уязвимость CVE-2020-27820