CVE-2020-14356
published 2020-08-19CVE-2020-14356: A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.97%
58.1th percentile
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.7.10-1 (bookworm) | linux 5.7.10-1 (bookworm) |
| debian | linux | — | — |
| linux | linux_kernel | >= 0 < 5.7.10-1 | 5.7.10-1 |
| linux | linux_kernel | >= 0 < 5.7.10-1 | 5.7.10-1 |
| linux | linux_kernel | >= 0 < 5.7.10-1 | 5.7.10-1 |
| linux | linux_kernel | >= 0 < 5.7.10-1 | 5.7.10-1 |
| linux | linux_kernel | >= 0 < 4.15.0-118.119 | 4.15.0-118.119 |
| linux | linux_kernel | >= 0 < 5.4.0-45.49 | 5.4.0-45.49 |
| linux | linux_kernel | >= 4.10 < 4.14.189 | 4.14.189 |
| linux | linux_kernel | >= 4.14 < 4.14.194 | 4.14.194 |
| linux | linux_kernel | >= 4.15 < 4.19.134 | 4.19.134 |
| linux | linux_kernel | >= 4.19 < 4.19.140 | 4.19.140 |
| linux | linux_kernel | >= 4.20 < 5.4.53 | 5.4.53 |
| linux | linux_kernel | >= 4.5 < 4.9.231 | 4.9.231 |
| linux | linux_kernel | >= 4.9.0 < 4.9.233 | 4.9.233 |
| linux | linux_kernel | >= 5.5 < 5.7.10 | 5.7.10 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-3_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m4f8-m4jg-vm84: The Linux kernel 4
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-25220 [HIGH] CWE-416 GHSA-m4f8-m4jg-vm84: The Linux kernel 4
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
GHSA
GHSA-gm74-x573-mg64: A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5
ghsa_unreviewed·2022-05-24
CVE-2020-14356 [HIGH] CWE-476 GHSA-gm74-x573-mg64: A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2020-09-23·CVSS 5.5
CVE-2019-18808 [MEDIUM] linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that the AMD Cryptographic Coprocessor device driver in
the Linux kernel did not properly deallocate memory in some situations. A
local attacker could use this to cause a denial of service (memory
exhaustion). (CVE-2019-18808)
It was discovered that the Conexant 23885 TV card device driver for the
Linux kernel did not properly deallocate memory in some error conditions. A
local attacker could use this to cause a denial of service (memory
exhaustion). (CVE-2019-19054)
It was discovered that the ADIS16400 IIO IMU Driver for the Linux kernel
did not properly deallocate memor
OSV
CVE-2020-25220: The Linux kernel 4
osv·2020-09-10·CVSS 7.8
CVE-2020-25220 [HIGH] CVE-2020-25220: The Linux kernel 4
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
osv·2020-09-03·CVSS 5.5
CVE-2019-20810 [MEDIUM] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
Chuhong Yuan discovered that go7007 USB audio device driver in the Linux
kernel did not properly deallocate memory in some failure conditions. A
physically proximate attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2019-20810)
Fan Yang discovered that the mremap implementation in the Linux kernel did
not properly handle DAX Huge Pages. A local attacker with access to DAX
storage could use this to gain administrative privileges. (CVE-2020-10757)
It was discovered that the Linux kernel did not correctly apply Speculative
Store Bypass Disable (SSBD) mitigations in certain
OSV
CVE-2020-14356: A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5
osv·2020-08-19·CVSS 7.8
CVE-2020-14356 [HIGH] CVE-2020-14356: A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-09-23·CVSS 5.5
CVE-2019-18808 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the AMD Cryptographic Coprocessor device driver in
the Linux kernel did not properly deallocate memory in some situations. A
local attacker could use this to cause a denial of service (memory
exhaustion). (CVE-2019-18808)
It was discovered that the Conexant 23885 TV card device driver for the
Linux kernel did not properly deallocate memory in some error conditions. A
local attacker could use this to cause a denial of service (memory
exhaustion). (CVE-2019-19054)
It was discovered that the ADIS16400 IIO IMU Driver for the Linux kernel
did not properly deallocate memory in certain error conditions. A local
attacker could use this to cause a denial of service (memory
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2020-09-03·CVSS 5.5
CVE-2019-20810 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Chuhong Yuan discovered that go7007 USB audio device driver in the Linux
kernel did not properly deallocate memory in some failure conditions. A
physically proximate attacker could use this to cause a denial of service
(memory exhaustion). (CVE-2019-20810)
Fan Yang discovered that the mremap implementation in the Linux kernel did
not properly handle DAX Huge Pages. A local attacker with access to DAX
storage could use this to gain administrative privileges. (CVE-2020-10757)
It was discovered that the Linux kernel did not correctly apply Speculative
Store Bypass Disable (SSBD) mitigations in certain situations. A local
attacker could possibly use this to expose sensitive information.
(CV
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2020-09-02
CVE-2020-14356 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
It was discovered that the cgroup v2 subsystem in the Linux kernel did not
properly perform reference counting in some situations, leading to a NULL
pointer dereference. A local attacker could use this to cause a denial of
service or possibly gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linu
Microsoft
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or es
vendor_msrc·2020-08-11·CVSS 7.8
CVE-2020-14356 [HIGH] CWE-476 A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or es
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional prod
Red Hat
kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356
vendor_redhat·2020-07-22·CVSS 7.8
CVE-2020-25220 [HIGH] CWE-416 kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356
kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
A flaw was found in the Linux kernel. The cgroups feature is affected by a use-after-free memory flaw that was not considered during the backport for CVE-2020-14356. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not
Red Hat
kernel: Use After Free vulnerability in cgroup BPF component
vendor_redhat·2020-05-31·CVSS 7.8
CVE-2020-14356 [HIGH] CWE-416 kernel: Use After Free vulnerability in cgroup BPF component
kernel: Use After Free vulnerability in cgroup BPF component
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
A use-after-free flaw was found in the Linux kernel’s cgroupv2 subsystem when rebooting the system. This flaw allows a local user to crash the system or escalate their privileges. The highest threat from this vulnerability is to system availability.
Statement: This flaw is rated as a having Moderate impact, because only local user can trigger it and no way to trigger it before reboot happens (until user have complete privileges for accessing cgroupv2).
Package: kernel (Red Hat Enterprise Lin
Debian
CVE-2020-14356: linux - A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versio...
vendor_debian·2020·CVSS 7.8
CVE-2020-14356 [HIGH] CVE-2020-14356: linux - A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versio...
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
Scope: local
bookworm: resolved (fixed in 5.7.10-1)
bullseye: resolved (fixed in 5.7.10-1)
forky: resolved (fixed in 5.7.10-1)
sid: resolved (fixed in 5.7.10-1)
trixie: resolved (fixed in 5.7.10-1)
Debian
CVE-2020-25220: linux - The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before...
vendor_debian·2020·CVSS 7.8
CVE-2020-25220 [HIGH] CVE-2020-25220: linux - The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before...
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25220 kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356
bugzilla·2020-09-10·CVSS 7.8
CVE-2020-25220 [HIGH] CVE-2020-25220 kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356
CVE-2020-25220 kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
Reference:
https://bugzilla.redhat.com/show_bug.cgi?id=1868453
Upstream commit:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-4.14.y&id=82fd2138a5ffd7e0d4320cdb669e115ee976a26e
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1877922]
---
Fedora does not support the 4.x LTS releases.
---
This bug is now closed. Further updates for individual products will be ref
Bugzilla
CVE-2020-25220 kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356 [fedora-all]
bugzilla·2020-09-10·CVSS 7.8
CVE-2020-25220 [HIGH] CVE-2020-25220 kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356 [fedora-all]
CVE-2020-25220 kernel: use-after-free because skcd->no_refcnt was not considered during the backport of CVE-2020-14356 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2020-14356 kernel: Use After Free vulnerability in cgroup BPF component
bugzilla·2020-08-12·CVSS 7.8
CVE-2020-14356 [HIGH] CVE-2020-14356 kernel: Use After Free vulnerability in cgroup BPF component
CVE-2020-14356 kernel: Use After Free vulnerability in cgroup BPF component
It was found that the Linux kernel's use after free issue could happen during the usage of cgroupv2 (usually when reboot and more likely if virtual machine or docker being used).
After recent commit 090e28b ("netprio_cgroup: Fix unlimited memory leak of v2 cgroups") was merged, the problem could be reproduced much simpler starting with 5.7.x kernels.
The problem introduced with 4.5 kernel, but there is no known way to trigger it, so it was not known until 5.7 kernel.
It could be possible to reproduce the bug by the user without privileges and without reboot if user has an ability to create/close cgroupv2 or this user create a process which is attached to already existing cgroupv2 BPF (but still the user will have
Bugzilla
CVE-2020-14356 kernel: Use After Free vulnerability in cgroup BPF component [fedora-all]
bugzilla·2020-08-12·CVSS 7.8
CVE-2020-14356 [HIGH] CVE-2020-14356 kernel: Use After Free vulnerability in cgroup BPF component [fedora-all]
CVE-2020-14356 kernel: Use After Free vulnerability in cgroup BPF component [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.htmlhttps://bugzilla.kernel.org/show_bug.cgi?id=208003https://bugzilla.redhat.com/show_bug.cgi?id=1868453https://lists.debian.org/debian-lts-announce/2020/09/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2020/10/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2020/10/msg00034.htmlhttps://lore.kernel.org/netdev/CAM_iQpUKQJrj8wE+Qa8NGR3P0L+5Uz=qo-O5+k_P60HzTde6aw%40mail.gmail.com/t/https://security.netapp.com/advisory/ntap-20200904-0002/https://usn.ubuntu.com/4483-1/https://usn.ubuntu.com/4484-1/https://usn.ubuntu.com/4526-1/http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.htmlhttps://bugzilla.kernel.org/show_bug.cgi?id=208003https://bugzilla.redhat.com/show_bug.cgi?id=1868453https://lists.debian.org/debian-lts-announce/2020/09/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2020/10/msg00032.htmlhttps://lists.debian.org/debian-lts-announce/2020/10/msg00034.htmlhttps://lore.kernel.org/netdev/CAM_iQpUKQJrj8wE+Qa8NGR3P0L+5Uz=qo-O5+k_P60HzTde6aw%40mail.gmail.com/t/https://security.netapp.com/advisory/ntap-20200904-0002/https://usn.ubuntu.com/4483-1/https://usn.ubuntu.com/4484-1/https://usn.ubuntu.com/4526-1/
2020-08-19
Published