CVE-2020-14416
published 2020-06-18CVE-2020-14416: In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka…
PriorityP414medium4.2CVSS 3.1
AVLACLPRHUIRSUCNINAH
EPSS
0.31%
23.3th percentile
In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.4.19-1 (bookworm) | linux 5.4.19-1 (bookworm) |
| linux | linux_kernel | < 5.4.16 | 5.4.16 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 5.4.19-1 | 5.4.19-1 |
| linux | linux_kernel | >= 0 < 4.4.0-184.214 | 4.4.0-184.214 |
| linux | linux_kernel | >= 0 < 4.15.0-112.113 | 4.15.0-112.113 |
| linux | linux_kernel | >= 0 < 5.4.0-45.49 | 5.4.0-45.49 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.2MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-whm7-h297-5ccm: In the Linux kernel before 5
ghsa_unreviewed·2022-05-24
CVE-2020-14416 [HIGH] CWE-362 GHSA-whm7-h297-5ccm: In the Linux kernel before 5
In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.
OSV
Kernel Live Patch Security Notice
osv·2020-07-27·CVSS 5.5
CVE-2019-19462 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
Relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local
users to cause a denial of service (such as relay blockage) by triggering a
NULL alloc_percpu result. (CVE-2019-19462)
Fan Yang discovered that the mremap implementation in the Linux kernel did
not properly handle DAX Huge Pages. A local attacker with access to DAX
storage could use this to gain administrative privileges. (CVE-2020-10757)
It was discovered that the DesignWare SPI controller driver in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash). (CVE-2020-12769)
In the Linux kernel before 5.4.16, a race condition in tty->disc_data
handling in the slip and slcan line discipline could lead to a
u
OSV
CVE-2020-14416: In the Linux kernel before 5
osv·2020-06-18·CVSS 4.2
CVE-2020-14416 [MEDIUM] CVE-2020-14416: In the Linux kernel before 5
In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2020-07-27·CVSS 5.5
CVE-2020-14416 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
Relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local
users to cause a denial of service (such as relay blockage) by triggering a
NULL alloc_percpu result. (CVE-2019-19462)
Fan Yang discovered that the mremap implementation in the Linux kernel did
not properly handle DAX Huge Pages. A local attacker with access to DAX
storage could use this to gain administrative privileges. (CVE-2020-10757)
It was discovered that the DesignWare SPI controller driver in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash). (CVE-2020-12769)
In the Linux kernel before 5.4.16, a race condition in tty->disc_da
Red Hat
kernel: slcan : race over tty->disc_data can lead use-after-free
vendor_redhat·2020-06-18·CVSS 4.2
CVE-2020-14416 [MEDIUM] CWE-416 kernel: slcan : race over tty->disc_data can lead use-after-free
kernel: slcan : race over tty->disc_data can lead use-after-free
In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.
A use-after-free flaw was found in slcan_write_wakeup in drivers/net/can/slcan.c in the serial CAN module slcan. A race condition occurs when communicating with can using slcan between the write (scheduling the transmit) and closing (flushing out any pending queues) the SLCAN channel. This flaw allows a local attacker with special user or root privileges to cause a denial of service or a kernel information leak. The highest threat from this vulnerability is to system availability.
Mitigatio
Debian
CVE-2020-14416: linux - In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling i...
vendor_debian·2020·CVSS 4.2
CVE-2020-14416 [MEDIUM] CVE-2020-14416: linux - In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling i...
In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.
Scope: local
bookworm: resolved (fixed in 5.4.19-1)
bullseye: resolved (fixed in 5.4.19-1)
forky: resolved (fixed in 5.4.19-1)
sid: resolved (fixed in 5.4.19-1)
trixie: resolved (fixed in 5.4.19-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1162002https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.16https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0ace17d56824165c7f4c68785d6b58971db954ddhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1162002https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.16https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0ace17d56824165c7f4c68785d6b58971db954dd
2020-06-18
Published