CVE-2020-12658
published 2020-12-31CVE-2020-12658: gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.68%
74.6th percentile
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | gssproxy | — | — |
| gssproxy_project | gssproxy | < 0.8.3 | 0.8.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
gssproxy: not unlocking cond_mutex before pthread exit in gp_worker_main() in gp_workers.c
vendor_redhat·2020-12-31·CVSS 9.8
CVE-2020-12658 [CRITICAL] CWE-667 gssproxy: not unlocking cond_mutex before pthread exit in gp_worker_main() in gp_workers.c
gssproxy: not unlocking cond_mutex before pthread exit in gp_worker_main() in gp_workers.c
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.
Statement: Red Hat Product Security does not view this as a security vulnerability because no service will be denied since the bug is triggered on an exit path of the program, which means that the program would already be stopping service and thus a malicious attacker would gain no impact to availability by triggering the bug.
Debian
CVE-2020-12658: gssproxy - gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread ...
vendor_debian·2020·CVSS 9.8
CVE-2020-12658 [CRITICAL] CVE-2020-12658: gssproxy - gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread ...
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-p2qg-cv6r-5429: gssproxy (aka gss-proxy) before 0
ghsa_unreviewed·2022-05-24
CVE-2020-12658 [CRITICAL] CWE-667 GHSA-p2qg-cv6r-5429: gssproxy (aka gss-proxy) before 0
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c.
OSV
CVE-2020-12658: ** DISPUTED ** gssproxy (aka gss-proxy) before 0
osv·2020-12-31·CVSS 9.8
CVE-2020-12658 [CRITICAL] CVE-2020-12658: ** DISPUTED ** gssproxy (aka gss-proxy) before 0
** DISPUTED ** gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem."
OSV
CVE-2020-12658: gssproxy (aka gss-proxy) before 0
osv·2020-12-31·CVSS 9.8
CVE-2020-12658 [CRITICAL] CVE-2020-12658: gssproxy (aka gss-proxy) before 0
gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/gssapi/gssproxy/commit/cb761412e299ef907f22cd7c4146d50c8a792003https://github.com/gssapi/gssproxy/compare/v0.8.2...v0.8.3https://lists.debian.org/debian-lts-announce/2021/01/msg00004.htmlhttps://pagure.io/gssproxy/c/cb761412e299ef907f22cd7c4146d50c8a792003?branch=masterhttps://github.com/gssapi/gssproxy/commit/cb761412e299ef907f22cd7c4146d50c8a792003https://github.com/gssapi/gssproxy/compare/v0.8.2...v0.8.3https://lists.debian.org/debian-lts-announce/2021/01/msg00004.htmlhttps://pagure.io/gssproxy/c/cb761412e299ef907f22cd7c4146d50c8a792003?branch=master
2020-12-31
Published