CVE-2020-12826

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.

References

https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.5

https://github.com/torvalds/linux/commit/7395ea4e65c2a00d23185a3f63ad315756ba9cef

https://www.openwall.com/lists/kernel-hardening/2020/03/25/1

https://lists.openwall.net/linux-kernel/2020/03/24/1803

https://bugzilla.redhat.com/show_bug.cgi?id=1822077

https://usn.ubuntu.com/4367-1/

https://usn.ubuntu.com/4369-1/

https://security.netapp.com/advisory/ntap-20200608-0001/

https://lists.debian.org/debian-lts-announce/2020/06/msg00011.html

https://lists.debian.org/debian-lts-announce/2020/06/msg00013.html

https://usn.ubuntu.com/4391-1/

Details

Source: MITRE

Published: 2020-05-12

Updated: 2020-06-22

Type: CWE-190

Risk Information

CVSS v2

Base Score: 4.4

Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 3.4

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Impact Score: 3.4

Exploitability Score: 1.8

Severity: MEDIUM

Tenable Plugins

View all (23 total)

IDNameProductFamilySeverity
145806CentOS 8 : kernel (CESA-2020:4431)NessusCentOS Local Security Checks
medium
142430RHEL 8 : kernel (RHSA-2020:4431)NessusRed Hat Local Security Checks
medium
142382RHEL 8 : kernel-rt (RHSA-2020:4609)NessusRed Hat Local Security Checks
medium
141727Scientific Linux Security Update : kernel on SL7.x x86_64 (20201001)NessusScientific Linux Local Security Checks
high
141619CentOS 7 : kernel (CESA-2020:4060)NessusCentOS Local Security Checks
high
141057RHEL 7 : kernel (RHSA-2020:4060)NessusRed Hat Local Security Checks
high
141026RHEL 7 : kernel-rt (RHSA-2020:4062)NessusRed Hat Local Security Checks
high
140917EulerOS 2.0 SP3 : kernel (EulerOS-SA-2020-2150)NessusHuawei Local Security Checks
medium
140328EulerOS Virtualization for ARM 64 3.0.2.0 : kernel (EulerOS-SA-2020-1958)NessusHuawei Local Security Checks
high
140141EulerOS 2.0 SP5 : kernel (EulerOS-SA-2020-1920)NessusHuawei Local Security Checks
medium
138631Amazon Linux AMI : kernel (ALAS-2020-1382)NessusAmazon Linux Local Security Checks
high
137932EulerOS Virtualization 3.0.6.0 : kernel (EulerOS-SA-2020-1713)NessusHuawei Local Security Checks
medium
137805EulerOS Virtualization for ARM 64 3.0.6.0 : kernel (EulerOS-SA-2020-1698)NessusHuawei Local Security Checks
medium
137571Amazon Linux 2 : kernel (ALAS-2020-1440)NessusAmazon Linux Local Security Checks
high
137516EulerOS 2.0 SP2 : kernel (EulerOS-SA-2020-1674)NessusHuawei Local Security Checks
critical
137391Slackware 14.2 : Slackware 14.2 kernel (SSA:2020-163-01)NessusSlackware Local Security Checks
medium
137301Ubuntu 16.04 LTS : Linux kernel vulnerabilities (USN-4391-1)NessusUbuntu Local Security Checks
medium
137283Debian DLA-2241-2 : linux security updateNessusDebian Local Security Checks
medium
137190Photon OS 3.0: Linux PHSA-2020-3.0-0100NessusPhotonOS Local Security Checks
medium
136870EulerOS 2.0 SP8 : kernel (EulerOS-SA-2020-1592)NessusHuawei Local Security Checks
high
136759Ubuntu 18.04 LTS / 19.10 : Linux kernel vulnerabilities (USN-4369-1)NessusUbuntu Local Security Checks
high
136732Ubuntu 20.04 : Linux kernel vulnerabilities (USN-4367-1)NessusUbuntu Local Security Checks
high
136627Amazon Linux AMI : kernel (ALAS-2020-1366)NessusAmazon Linux Local Security Checks
high