CVE-2020-12826
published 2020-05-12CVE-2020-12826: A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits…
PriorityP430medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.71%
49.6th percentile
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 5.6.7-1 (bookworm) | linux 5.6.7-1 (bookworm) |
| linux | linux_kernel | < 5.6.5 | 5.6.5 |
| linux | linux_kernel | >= 0 < 5.6.7-1 | 5.6.7-1 |
| linux | linux_kernel | >= 0 < 5.6.7-1 | 5.6.7-1 |
| linux | linux_kernel | >= 0 < 5.6.7-1 | 5.6.7-1 |
| linux | linux_kernel | >= 0 < 5.6.7-1 | 5.6.7-1 |
| linux | linux_kernel | >= 0 < 4.4.0-184.214 | 4.4.0-184.214 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-3_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv6.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-06-11·CVSS 6.5
CVE-2019-19319 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle setxattr operations in some situations. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-19319)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
i
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-05-24·CVSS 7.8
CVE-2019-19377 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the btrfs implementation in the Linux kernel did not
properly detect that a block was marked dirty in some situations. An
attacker could use this to specially craft a file system image that, when
unmounted, could cause a denial of service (system crash). (CVE-2019-19377)
It was discovered that the linux kernel did not properly validate certain
mount options to the tmpfs virtual memory file system. A local attacker
with the ability to specify mount options could use this to cause a denial
of service (system crash). (CVE-2020-11565)
It was discovered that the block layer in the Linux kernel contained a race
condition leading to a use-after-free vulnerability. A loca
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-05-24·CVSS 7.8
CVE-2019-19377 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the btrfs implementation in the Linux kernel did not
properly detect that a block was marked dirty in some situations. An
attacker could use this to specially craft a file system image that, when
unmounted, could cause a denial of service (system crash). (CVE-2019-19377)
Tristan Madani discovered that the file locking implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service or expose sensitive information.
(CVE-2019-19769)
It was discovered that the Serial CAN interface driver in the Linux kernel
did not properly initialize data. A local attacker could use this to expose
sensitive informat
Microsoft
A signal access-control issue was discovered in the Linux kernel before 5.6.5 aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits an integer overflow can interfere with a do
vendor_msrc·2020-05-12·CVSS 5.3
CVE-2020-12826 [MEDIUM] CWE-190 A signal access-control issue was discovered in the Linux kernel before 5.6.5 aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits an integer overflow can interfere with a do
A signal access-control issue was discovered in the Linux kernel before 5.6.5 aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs and the lack of scenarios where signals to a parent process present a substantial operational threat.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date
Red Hat
kernel: possible to send arbitrary signals to a privileged (suidroot) parent process
vendor_redhat·2020-05-12·CVSS 5.3
CVE-2020-12826 [MEDIUM] CWE-94 kernel: possible to send arbitrary signals to a privileged (suidroot) parent process
kernel: possible to send arbitrary signals to a privileged (suidroot) parent process
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.
A flaw was found in the Linux kernel loose validation of child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw t
Debian
CVE-2020-12826: linux - A signal access-control issue was discovered in the Linux kernel before 5.6.5, a...
vendor_debian·2020·CVSS 5.3
CVE-2020-12826 [MEDIUM] CVE-2020-12826: linux - A signal access-control issue was discovered in the Linux kernel before 5.6.5, a...
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.
Scope: local
bookworm: resolved (fixed in 5.6.7-1)
bullseye: resolved (fixed in 5.6.7-1)
forky: resolved (fixed in 5.6.7-1)
sid: resolved (fixed in 5.6.7-1)
trixie: resolved (fixed in 5.6.7-1)
GHSA
GHSA-wxmm-482m-cm8h: A signal access-control issue was discovered in the Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2020-12826 [MEDIUM] CWE-190 GHSA-wxmm-482m-cm8h: A signal access-control issue was discovered in the Linux kernel before 5
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2020-06-11·CVSS 6.5
CVE-2019-19319 [MEDIUM] linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly handle setxattr operations in some situations. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-19319)
It was discovered that memory contents previously stored in
microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY
read operations on Intel client and Xeon E3 processors may be briefly
exposed to processes on the same or different processor cores. A local
attacker could use this to expose sensitive information. (CVE-2020-0543)
Piotr Krysiuk discovered that race conditions existed in the file system
implementation in the Linux
OSV
CVE-2020-12826: A signal access-control issue was discovered in the Linux kernel before 5
osv·2020-05-12·CVSS 5.3
CVE-2020-12826 [MEDIUM] CVE-2020-12826: A signal access-control issue was discovered in the Linux kernel before 5
A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1822077https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.5https://github.com/torvalds/linux/commit/7395ea4e65c2a00d23185a3f63ad315756ba9cefhttps://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://lists.openwall.net/linux-kernel/2020/03/24/1803https://security.netapp.com/advisory/ntap-20200608-0001/https://usn.ubuntu.com/4367-1/https://usn.ubuntu.com/4369-1/https://usn.ubuntu.com/4391-1/https://www.openwall.com/lists/kernel-hardening/2020/03/25/1https://bugzilla.redhat.com/show_bug.cgi?id=1822077https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6.5https://github.com/torvalds/linux/commit/7395ea4e65c2a00d23185a3f63ad315756ba9cefhttps://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://lists.openwall.net/linux-kernel/2020/03/24/1803https://security.netapp.com/advisory/ntap-20200608-0001/https://usn.ubuntu.com/4367-1/https://usn.ubuntu.com/4369-1/https://usn.ubuntu.com/4391-1/https://www.openwall.com/lists/kernel-hardening/2020/03/25/1
2020-05-12
Published