PT-2020-5340 · Linux+3 · Linux Kernel+3

Published

2020-09-30

·

Updated

2021-06-02

·

CVE-2020-29534

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.9.3
Description The issue is related to the io uring function in the Linux kernel, which is associated with errors in privilege assignment. Exploitation of this issue may allow an attacker to elevate their privileges. The problem arises because io uring takes a non-refcounted reference to the files struct of the process that submitted a request, causing execve() to incorrectly optimize unshare fd().
Recommendations For Linux kernel versions prior to 5.9.3, update to version 5.9.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of the io uring function until a patch is available.

Exploit

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3182
ALT-PU-2020-3211
ALT-PU-2020-3553
ALT-PU-2020-3570
ALT-PU-2021-1083
ALT-PU-2021-1105
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
BDU:2021-00137
CVE-2020-29534
MGASA-2021-0030
MGASA-2021-0031
USN-4678-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Ubuntu