CVE-2020-14381
Summary
| CVE | CVE-2020-14381 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-03 17:15:00 UTC |
| Updated | 2020-12-08 16:00:00 UTC |
| Description | A flaw was found in the Linux kernel’s futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1874311 – (CVE-2020-14381) CVE-2020-14381 kernel: referencing inode of removed superblock in get_futex_key() causes UAF |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
Mailing List, Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159684 Oracle Enterprise Linux Security Update for kernel (ELSA-2020-4431)
- 610357 Google Android Devices August 2021 Security Patch Missing
- 610366 Google Android September 2021 Security Patch Missing for Samsung
- 670744 EulerOS Security Update for kernel (EulerOS-SA-2021-2502)
- 900040 CBL-Mariner Linux Security Update for kernel 5.4.91
- 903162 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3650)
- 905965 Common Base Linux Mariner (CBL-Mariner) Security Update for kernel (3650-1)
- 940256 AlmaLinux Security Update for kernel (ALSA-2020:4431)