cbcvebase.
CVE-2020-16119
published 2021-01-14

CVE-2020-16119: Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.8th percentile
Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196.

Affected

24 ranges
VendorProductVersion rangeFixed in
canonicallinux_kernel>= 3.13 kernel < 3.13.0.182.1913.13.0.182.191
canonicallinux_kernel>= 3.2 kernel < 3.2.0-149.1963.2.0-149.196
canonicallinux_kernel>= 4.15 kernel < 4.15.0-121.1234.15.0-121.123
canonicallinux_kernel>= 4.4 kernel < 4.4.0-193.2244.4.0-193.224
canonicallinux_kernel>= 5.3 kernel < 5.3.0-68.635.3.0-68.63
canonicallinux_kernel>= 5.4 kernel < 5.4.0-51.565.4.0-51.56
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.14.6-1 (bookworm)linux 5.14.6-1 (bookworm)
linuxlinux_kernel>= 0 < 5.10.46-55.10.46-5
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 5.14.6-15.14.6-1
linuxlinux_kernel>= 0 < 4.4.0-193.2244.4.0-193.224
linuxlinux_kernel>= 0 < 4.15.0-121.1234.15.0-121.123
linuxlinux_kernel>= 0 < 5.4.0-51.565.4.0-51.56
linuxlinux_kernel>= 0 < 4.4.0-193.2244.4.0-193.224
linuxlinux_kernel>= 0 < 4.15.0-121.1234.15.0-121.123
linuxlinux_kernel>= 0 < 5.4.0-51.565.4.0-51.56

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.