PT-2020-1261 · Linux+5 · Linux Kernel+5

Jann Horn

·

Published

2020-03-06

·

Updated

2026-02-25

·

CVE-2020-14381

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the Linux kernel's futex implementation, which involves the use of memory after it has been freed. This could allow an attacker to corrupt system memory, escalate privileges, or impact the confidentiality, integrity, and availability of protected information. The threat is highest for local attackers who can create a futex on a filesystem that is about to be unmounted. Exploitation can lead to local escalation of privilege without needing additional execution privileges, and user interaction is not required.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4431
ALT-PU-2020-1638
ALT-PU-2020-1646
ALT-PU-2020-1761
ALT-PU-2020-1917
ALT-PU-2020-2153
ALT-PU-2020-2164
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
ASB-A-175193031
BDU:2020-05792
CESA-2020_4431
CESA-2020_4609
CVE-2020-14381
OESA-2021-1086
OPENSUSE-SU-2020:1655-1
OPENSUSE-SU-2020_1655-1
RHSA-2020:4431
RHSA-2020:4609
RHSA-2020_4431
RHSA-2020_4609
SUSE-SU-2020:2904-1
SUSE-SU-2020:2905-1
SUSE-SU-2020:2906-1
SUSE-SU-2020:2907-1
SUSE-SU-2020:2999-1
SUSE-SU-2020:3014-1
SUSE-SU-2020:3178-1
SUSE-SU-2020:3180-1
SUSE-SU-2020:3188-1
SUSE-SU-2020:3190-1
SUSE-SU-2020:3204-1
SUSE-SU-2020:3210-1
SUSE-SU-2020:3219-1
SUSE-SU-2020:3222-1
SUSE-SU-2020:3225-1
SUSE-SU-2020:3501-1
SUSE-SU-2020:3503-1
SUSE-SU-2020:3532-1
SUSE-SU-2020:3544-1
SUSE-SU-2020_3188-1
SUSE-SU-2021:14630-1
SUSE-SU-2021_14630-1

Affected Products

Alt Linux
Almalinux
Centos
Linux Kernel
Red Hat
Suse