Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-35508

Опубликовано: 09 дек. 2020
Источник: redhat
CVSS3: 4.5
EPSS Низкий

Описание

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

Отчет

The incorrect initialization of the process id affects Red Hat Enterprise Linux only.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise MRG 2kernel-rtNot affected
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2021:173918.05.2021
Red Hat Enterprise Linux 8kernelFixedRHSA-2021:157818.05.2021
Red Hat Enterprise Linux 8.2 Extended Update Supportkernel-rtFixedRHSA-2021:271920.07.2021
Red Hat Enterprise Linux 8.2 Extended Update SupportkernelFixedRHSA-2021:271820.07.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-665
https://bugzilla.redhat.com/show_bug.cgi?id=1902724kernel: fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent

EPSS

Процентиль: 18%
0.00056
Низкий

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
ubuntu
около 4 лет назад

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

CVSS3: 4.5
nvd
около 4 лет назад

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

CVSS3: 4.5
debian
около 4 лет назад

A flaw possibility of race condition and incorrect initialization of t ...

CVSS3: 4.5
github
около 3 лет назад

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

CVSS3: 4.5
fstec
больше 4 лет назад

Уязвимость ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 18%
0.00056
Низкий

4.5 Medium

CVSS3