CVE-2020-14351Use After Free in Kernel

CWE-416Use After Free22 documents9 sources
Severity
7.8HIGHNVD
OSV5.5
EPSS
0.1%
top 67.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 3
Latest updateFeb 14

Description

A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

NVDlinux/linux_kernel< 5.8.17
Debianlinux/linux_kernel< 5.9.6-1+3
Ubuntulinux/linux_kernel< 4.4.0-197.229+4
CVEListV5linux/linux_kernelkernel 5.8.17
debiandebian/linux< linux 5.9.6-1 (bookworm)

Also affects: Debian Linux 9.0, Enterprise Linux 7.0, 8.0

Patches

🔴Vulnerability Details

8
GHSA
GHSA-969c-xcr8-6f87: A flaw was found in the Linux kernel2022-05-24
OSV
linux-oem-5.6 vulnerabilities2021-04-13
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 regression2020-12-13
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-snapdragon regression2020-12-13
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities2020-12-03

📋Vendor Advisories

12
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS2024-02-14
Ubuntu
Linux kernel (OEM) vulnerabilities2021-04-13
Ubuntu
Linux kernel regression2020-12-13
Ubuntu
Linux kernel regression2020-12-13
Ubuntu
Linux kernel regression2020-12-13

💬Community

1
Bugzilla
CVE-2020-14351 kernel: performance counters race condition use-after-free2020-08-03