PT-2020-6166 · Linux+4 · Linux Kernel+4

Hadar Manor

+1

·

Published

2020-10-13

·

Updated

2025-09-29

·

CVE-2020-16119

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.4.0-51.56 Linux kernel versions prior to 5.3.0-68.63 Linux kernel versions prior to 4.15.0-121.123 Linux kernel versions prior to 4.4.0-193.224 Linux kernel versions prior to 3.13.0.182.191 Linux kernel versions prior to 3.2.0-149.196
Description The issue is related to a use-after-free vulnerability in the Linux kernel, which can be exploited by a local attacker. This occurs due to the reuse of a DCCP socket with an attached dccps hc tx ccid object as a listener after being released. This vulnerability allows an attacker to potentially access confidential information or cause a denial of service.
Recommendations For Linux kernel version 5.4.0-51.56 and earlier, update to Ubuntu Linux kernel 5.4.0-51.56 or later. For Linux kernel version 5.3.0-68.63 and earlier, update to Ubuntu Linux kernel 5.3.0-68.63 or later. For Linux kernel version 4.15.0-121.123 and earlier, update to Ubuntu Linux kernel 4.15.0-121.123 or later. For Linux kernel version 4.4.0-193.224 and earlier, update to Ubuntu Linux kernel 4.4.0-193.224 or later. For Linux kernel version 3.13.0.182.191 and earlier, update to Ubuntu Linux kernel 3.13.0.182.191 or later. For Linux kernel version 3.2.0-149.196 and earlier, update to Ubuntu Linux kernel 3.2.0-149.196 or later.

Exploit

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2021-2870
ALT-PU-2021-2882
ALT-PU-2021-2906
ALT-PU-2021-2907
ALT-PU-2021-2912
ALT-PU-2021-2913
ALT-PU-2021-2919
ALT-PU-2021-2923
ALT-PU-2021-2938
ALT-PU-2021-2984
BDU:2021-03395
CVE-2020-16119
DLA-2785-1
DLA-2843-1
DSA-4978-1
LSN-0072-1
MGASA-2021-0459
MGASA-2021-0460
OESA-2021-1429
OPENSUSE-SU-2022_3609-1
OPENSUSE-SU-2022_3775-1
OPENSUSE-SU-2022_4617-1
SUSE-SU-2022:3609-1
SUSE-SU-2022:3704-1
SUSE-SU-2022:3775-1
SUSE-SU-2022:3809-1
SUSE-SU-2022:4617-1
SUSE-SU-2023:0416-1
USN-4576-1
USN-4577-1
USN-4578-1
USN-4579-1
USN-4580-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu