CVE-2020-16119
Summary
| CVE | CVE-2020-16119 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-14 01:15:00 UTC |
| Updated | 2023-11-07 03:18:00 UTC |
| Description | Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [PATCH 0/2] net: dccp: fix structure use-after-free |
|
lore.kernel.org |
|
| [PATCH 0/2] net: dccp: fix structure use-after-free |
CONFIRM |
lore.kernel.org |
Patch, Vendor Advisory |
| USN-4578-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
ubuntu.com |
Third Party Advisory |
| USN-4580-1: Linux kernel vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
ubuntu.com |
Third Party Advisory |
| Bug #1883840 “Double free in DCCP module causing kernel panic” : Bugs : linux package : Ubuntu |
UBUNTU |
launchpad.net |
Issue Tracking, Patch, Third Party Advisory |
| CVE-2020-16119 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| USN-4576-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
ubuntu.com |
Third Party Advisory |
| USN-4577-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
ubuntu.com |
Third Party Advisory |
| [SECURITY] [DLA 2785-1] linux-4.19 security update |
MLIST |
lists.debian.org |
|
| ~ubuntu-kernel/ubuntu/+source/linux/+git/focal - [no description] |
UBUNTU |
git.launchpad.net |
Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4978-1 linux |
DEBIAN |
www.debian.org |
|
| [SECURITY] [DLA 2843-1] linux security update |
MLIST |
lists.debian.org |
|
| USN-4579-1: Linux kernel vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
ubuntu.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Hador Manor
Legacy QID Mappings
- 159425 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9486)
- 159426 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel-container (ELSA-2021-9487)
- 178809 Debian Security Update for linux (DSA 4978-1)
- 178844 Debian Security Update for linux-4.19 (DLA 2785-1)
- 178943 Debian Security Update for linux (DLA 2843-1)
- 352871 Amazon Linux Security Advisory for kernel : ALAS-2021-1539
- 353143 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.4-2022-008
- 353154 Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.10-2022-006
- 6140041 AWS Bottlerocket Security Update for kernel (GHSA-jwcc-6vcr-3r9c)
- 671295 EulerOS Security Update for kernel (EulerOS-SA-2022-1243)
- 752708 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3704-1)
- 752724 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3775-1)
- 753063 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:4617-1)
- 753370 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3609-1)
- 753374 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2022:3809-1)
- 753703 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 753707 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)
- 753727 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2023:0416-1)