CVE-2020-12657

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.

References

http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00022.html

https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.5

https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=2f95fa5c955d0a9987ffdc3a095e2f4e62c5f2a9

https://github.com/torvalds/linux/commit/2f95fa5c955d0a9987ffdc3a095e2f4e62c5f2a9

https://patchwork.kernel.org/patch/11447049/

https://security.netapp.com/advisory/ntap-20200608-0001/

https://usn.ubuntu.com/4363-1/

https://usn.ubuntu.com/4367-1/

https://usn.ubuntu.com/4368-1/

https://usn.ubuntu.com/4369-1/

Details

Source: MITRE

Published: 2020-05-05

Updated: 2020-06-13

Type: CWE-416

Risk Information

CVSS v2

Base Score: 4.6

Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.9

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Tenable Plugins

View all (27 total)

IDNameProductFamilySeverity
145853CentOS 8 : kernel (CESA-2020:2427)NessusCentOS Local Security Checks
high
140378SUSE SLES15 Security Update : kernel (SUSE-SU-2020:2487-1)NessusSuSE Local Security Checks
medium
138766NewStart CGSL MAIN 6.01 : kernel Multiple Vulnerabilities (NS-SA-2020-0030)NessusNewStart CGSL Local Security Checks
critical
138679openSUSE Security Update : the Linux Kernel (openSUSE-2020-801)NessusSuSE Local Security Checks
medium
138631Amazon Linux AMI : kernel (ALAS-2020-1382)NessusAmazon Linux Local Security Checks
high
138418Oracle Linux 7 : Unbreakable Enterprise kernel (ELSA-2020-5755)NessusOracle Linux Local Security Checks
high
138272SUSE SLES15 Security Update : kernel (SUSE-SU-2020:1663-1)NessusSuSE Local Security Checks
critical
137832RHEL 8 : kernel (RHSA-2020:2667)NessusRed Hat Local Security Checks
high
137617SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1605-1)NessusSuSE Local Security Checks
medium
137616SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1603-1)NessusSuSE Local Security Checks
medium
137615SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1602-1)NessusSuSE Local Security Checks
medium
137613SUSE SLED15 / SLES15 Security Update : kernel (SUSE-SU-2020:1599-1)NessusSuSE Local Security Checks
medium
137608SUSE SLES12 Security Update : kernel (SUSE-SU-2020:1587-1)NessusSuSE Local Security Checks
medium
137571Amazon Linux 2 : kernel (ALAS-2020-1440)NessusAmazon Linux Local Security Checks
high
137384Oracle Linux 8 : kernel (ELSA-2020-2427)NessusOracle Linux Local Security Checks
high
137290Oracle Linux 7 / 8 : Unbreakable Enterprise kernel (ELSA-2020-5714)NessusOracle Linux Local Security Checks
medium
137278RHEL 8 : kernel (RHSA-2020:2427)NessusRed Hat Local Security Checks
high
137275RHEL 8 : kernel (RHSA-2020:2429)NessusRed Hat Local Security Checks
high
137274RHEL 8 : kernel-rt (RHSA-2020:2428)NessusRed Hat Local Security Checks
high
136966Ubuntu 18.04 LTS / 19.10 : Linux kernel regression (USN-4369-2)NessusUbuntu Local Security Checks
high
136965Ubuntu 20.04 : Linux kernel regression (USN-4367-2)NessusUbuntu Local Security Checks
high
136870EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-1592)NessusHuawei Local Security Checks
high
136759Ubuntu 18.04 LTS / 19.10 : Linux kernel vulnerabilities (USN-4369-1)NessusUbuntu Local Security Checks
high
136733Ubuntu 18.04 LTS : Linux kernel vulnerabilities (USN-4368-1)NessusUbuntu Local Security Checks
medium
136732Ubuntu 20.04 : Linux kernel vulnerabilities (USN-4367-1)NessusUbuntu Local Security Checks
high
136710Ubuntu 16.04 LTS / 18.04 LTS : Linux kernel vulnerabilities (USN-4363-1)NessusUbuntu Local Security Checks
high
136627Amazon Linux AMI : kernel (ALAS-2020-1366)NessusAmazon Linux Local Security Checks
high