CVE-2020-27825
published 2020-12-11CVE-2020-27825: A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu…
PriorityP423medium5.7CVSS 3.1
AVLACHPRHUINSUCHINAH
EPSS
0.28%
19.5th percentile
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.9.6-1 (bookworm) | linux 5.9.6-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H
nvdv2.05.4MEDIUMAV:L/AC:M/Au:N/C:P/I:N/A:C
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: use-after-free in the ftrace ring buffer resizing logic due to a race condition
vendor_redhat·2020-10-06·CVSS 5.7
CVE-2020-27825 [MEDIUM] CWE-362 kernel: use-after-free in the ftrace ring buffer resizing logic due to a race condition
kernel: use-after-free in the ftrace ring buffer resizing logic due to a race condition
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel. There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
Mitigation: Mitigation
Debian
CVE-2020-27825: linux - A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (b...
vendor_debian·2020·CVSS 5.7
CVE-2020-27825 [MEDIUM] CVE-2020-27825: linux - A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (b...
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
Scope: local
bookworm: resolved (fixed in 5.9.6-1)
bullseye: resolved (fixed in 5.9.6-1)
forky: resolved (fixed in 5.9.6-1)
sid: resolved (fixed in 5.9.6-1)
trixie: resolved (fixed in 5.9.6-1)
GHSA
GHSA-wx9f-x53v-pqrr: A use-after-free flaw was found in kernel/trace/ring_buffer
ghsa_unreviewed·2022-05-24
CVE-2020-27825 [MEDIUM] CWE-362 GHSA-wx9f-x53v-pqrr: A use-after-free flaw was found in kernel/trace/ring_buffer
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running in parallel on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
OSV
CVE-2020-27825: A use-after-free flaw was found in kernel/trace/ring_buffer
osv·2020-12-11·CVSS 5.7
CVE-2020-27825 [MEDIUM] CVE-2020-27825: A use-after-free flaw was found in kernel/trace/ring_buffer
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.
No detection rules found.
No public exploits indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1905155https://lists.debian.org/debian-lts-announce/2021/02/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00010.htmlhttps://security.netapp.com/advisory/ntap-20210521-0008/https://www.debian.org/security/2021/dsa-4843https://bugzilla.redhat.com/show_bug.cgi?id=1905155https://lists.debian.org/debian-lts-announce/2021/02/msg00018.htmlhttps://lists.debian.org/debian-lts-announce/2021/03/msg00010.htmlhttps://security.netapp.com/advisory/ntap-20210521-0008/https://www.debian.org/security/2021/dsa-4843
2020-12-11
Published