cbcvebase.
CVE-2020-10690
published 2020-05-08

CVE-2020-10690: There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a…

PriorityP427medium6.4CVSS 3.1
AVLACHPRHUINSUCHIHAH
EPSS
0.36%
28.1th percentile
There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition as the process wakes up to terminate and clean all attached files. The system crashes due to the cdev structure being invalid (as already freed) which is pointed to by the inode.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.4.8-1 (bookworm)linux 5.4.8-1 (bookworm)
linuxlinux_kernel< 5.55.5
linuxlinux_kernel>= 0 < 5.4.8-15.4.8-1
linuxlinux_kernel>= 0 < 5.4.8-15.4.8-1
linuxlinux_kernel>= 0 < 5.4.8-15.4.8-1
linuxlinux_kernel>= 0 < 5.4.8-15.4.8-1
linuxlinux_kernel>= 0 < 4.4.0-185.2154.4.0-185.215
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.4.91-3_on_cbl_mariner_1.0
opensuseleap
red_hatkernel
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.16.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv6.4MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_msrc6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.