CVE-2020-15436
published 2020-11-23CVE-2020-15436: Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging…
PriorityP427medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.93%
57.1th percentile
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.7.6-1 (bookworm) | linux 5.7.6-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.7.6-1 | 5.7.6-1 |
| linux | linux_kernel | >= 0 < 5.7.6-1 | 5.7.6-1 |
| linux | linux_kernel | >= 0 < 5.7.6-1 | 5.7.6-1 |
| linux | linux_kernel | >= 0 < 5.7.6-1 | 5.7.6-1 |
| linux | linux_kernel | >= 2.6.38 < 4.4.229 | 4.4.229 |
| linux | linux_kernel | >= 4.10 < 4.14.186 | 4.14.186 |
| linux | linux_kernel | >= 4.15 < 4.19.130 | 4.19.130 |
| linux | linux_kernel | >= 4.20 < 5.4.49 | 5.4.49 |
| linux | linux_kernel | >= 4.5 < 4.9.229 | 4.9.229 |
| linux | linux_kernel | >= 5.5 < 5.7.6 | 5.7.6 |
| msrc | cm1_kernel_5.4.91-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv6.7MEDIUM
vendor_debian6.7MEDIUM
vendor_msrc6.7MEDIUM
vendor_redhat6.7MEDIUM
vendor_ubuntu5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pcpr-hxm8-3mj4: Use-after-free vulnerability in fs/block_dev
ghsa_unreviewed·2022-05-24
CVE-2020-15436 [HIGH] CWE-416 GHSA-pcpr-hxm8-3mj4: Use-after-free vulnerability in fs/block_dev
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
OSV
CVE-2020-15436: In blkdev_get of block_dev
osv·2021-04-01
CVE-2020-15436 CVE-2020-15436: In blkdev_get of block_dev
In blkdev_get of block_dev.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
linux-oem-5.6 vulnerabilities
osv·2021-02-25·CVSS 5.4
CVE-2020-10135 [MEDIUM] linux-oem-5.6 vulnerabilities
linux-oem-5.6 vulnerabilities
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)
It was discovered that the block layer implementation in the Linux kernel
did not prope
OSV
CVE-2020-15436: Use-after-free vulnerability in fs/block_dev
osv·2020-11-23·CVSS 6.7
CVE-2020-15436 [MEDIUM] CVE-2020-15436: Use-after-free vulnerability in fs/block_dev
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
CISA ICS
Siemens SIMATIC
cisa_ics·2024-03-14
Siemens SIMATIC
ICS Advisory
##
Siemens SIMATIC
Release DateMarch 14, 2024
Alert CodeICSA-24-074-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC
- Vulnerabilities: Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Input Validation, Missing Encryption of Sensitive Data, Incorrect Permission Assignment for Critical Resource, Expected Beha
Android
CVE-2020-15436: Kernel Block Device Subsystem
vendor_android·2021-04-01·CVSS 6.7
CVE-2020-15436 [MEDIUM] CVE-2020-15436: Kernel Block Device Subsystem
Android Security Bulletin 2021-04-01
CVE: CVE-2020-15436
Severity: HIGH
Type: EoP
Component: Kernel Block Device Subsystem
References: A-174737742
Upstream kernel
Ubuntu
Linux kernel (OEM) vulnerabilities
vendor_ubuntu·2021-02-25·CVSS 5.4
CVE-2020-27152 [MEDIUM] Linux kernel (OEM) vulnerabilities
Title: Linux kernel (OEM) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenticated user to complete
authentication without pairing credentials via adjacent access. A
physically proximate attacker could use this to impersonate a previously
paired Bluetooth device. (CVE-2020-10135)
Jay Shin discovered that the ext4 file system implementation in the Linux
kernel did not properly handle directory access with broken indexing,
leading to an out-of-bounds read vulnerability. A local attacker could use
this to cause a denial of service (system crash). (CVE-2020-14314)
It was di
Microsoft
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
vendor_msrc·2020-11-10·CVSS 6.7
CVE-2020-15436 [MEDIUM] CWE-416 Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the
Red Hat
kernel: use-after-free in fs/block_dev.c
vendor_redhat·2020-06-08·CVSS 6.7
CVE-2020-15436 [MEDIUM] CWE-416 kernel: use-after-free in fs/block_dev.c
kernel: use-after-free in fs/block_dev.c
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
A use-after-free flaw was observed in blkdev_get(), in fs/block_dev.c after a call to __blkdev_get() fails, and its refcount gets freed/released. This problem may cause a denial of service problem with a special user privilege, and may even lead to a confidentiality issue.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: kernel (Red Hat Enterprise
Debian
CVE-2020-15436: linux - Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 al...
vendor_debian·2020·CVSS 6.7
CVE-2020-15436 [MEDIUM] CVE-2020-15436: linux - Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 al...
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field.
Scope: local
bookworm: resolved (fixed in 5.7.6-1)
bullseye: resolved (fixed in 5.7.6-1)
forky: resolved (fixed in 5.7.6-1)
sid: resolved (fixed in 5.7.6-1)
trixie: resolved (fixed in 5.7.6-1)
No detection rules found.
No public exploits indexed.
Qualys
Google Android April 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices | Qualys
blogs_qualys·2021-04-12·CVSS 9.3
[CRITICAL] Google Android April 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices | Qualys
The recently released Android Security Bulletin for April 2021 addresses 36 vulnerabilities, out of which 2 are rated as critical vulnerabilities. The vulnerabilities affect open-source components such as the Android Framework, Android Media Framework, Android System, and Android’s Linux Kernel fork. The vulnerabilities also affect MediaTek and QUALCOMM closed-source components.
##### Android System Remote Code Execution (RCE) Vulnerability
Google released a patch to fix a critical RCE vulnerability (CVE-2021-0430). This vulnerability has a CVSSv3 base score of 8.8 and should be prioritized for patching. It affects Android versions 10 and 11.
##### QUALCOMM Closed-Source Components Elevation of Privilege (EoP) Vulnerability
Google released a patch to fix a critical EoP vulnerability (C
Qualys
Google Android April 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices
blogs_qualys·2021-04-12·CVSS 9.3
[CRITICAL] Google Android April 2021 Security Patch Vulnerabilities: Discover and Take Remote Response Action Using VMDR for Mobile Devices
The recently released Android Security Bulletin for April 2021 addresses 36 vulnerabilities, out of which 2 are rated as critical vulnerabilities. The vulnerabilities affect open-source components such as the Android Framework, Android Media Framework, Android System, and Android’s Linux Kernel fork. The vulnerabilities also affect MediaTek and QUALCOMM closed-source components.
## Android System Remote Code Execution (RCE) Vulnerability
Google released a patch to fix a critical RCE vulnerability (CVE-2021-0430). This vulnerability has a CVSSv3 base score of 8.8 and should be prioritized for patching. It affects Android versions 10 and 11.
## QUALCOMM Closed-Source Components Elevation of Privilege (EoP) Vulnerability
Google released a patch to fix a critical EoP vulnerability (CVE-202
2020-11-23
Published