Wind River Support Network

HomeDefectsLIN1018-6972
Fixed

LIN1018-6972 : Security Advisory - linux - CVE-2020-27786

Created: Dec 6, 2020    Updated: Jan 17, 2021
Resolved Date: Jan 4, 2021
Found In Version: 10.18.44.1
Fix Version: 10.18.44.21
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Kernel

Description

The rawmidi core allows user to resize the runtime buffer via ioctl,
and this may lead to UAF when performed during concurrent reads or writes: the read/write functions unlock the runtime lock temporarily during copying form/to user-space,
and that's the race window.

Patch for this issue:

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c1f6e3c818dd734c30f6a7eeebf232ba2cf3181d

CREATE(Triage):(User=admin) [CVE-2020-27786|https://nvd.nist.gov/vuln/detail/CVE-2020-27786]

CVEs


Live chat
Online