CVE-2020-27786
Summary
| CVE | CVE-2020-27786 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-11 05:15:00 UTC |
| Updated | 2023-05-16 10:49:00 UTC |
| Description | A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of execution to change and possibly allow for memory corruption or privilege escalation. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2020-27786 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| 1900933 – (CVE-2020-27786) CVE-2020-27786 kernel: use-after-free in kernel midi subsystem |
MISC |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| oss-security - Re: Linux Kernel: ALSA: use-after-free Write in snd_rawmidi_kernel_write1 |
MLIST |
www.openwall.com |
|
| kernel/git/torvalds/linux.git - Linux kernel source tree |
MISC |
git.kernel.org |
Patch, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159185 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-1578)
- 174806 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP2) (SUSE-SU-2021:0835-1)
- 174808 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP2) (SUSE-SU-2021:0870-1)
- 174810 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (SUSE-SU-2021:0853-1)
- 174812 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 13 for SLE 15 SP1) (SUSE-SU-2021:0859-1)
- 174813 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 5 for SLE 12 SP5) (SUSE-SU-2021:0818-1)
- 174818 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 14 for SLE 12 SP5) (SUSE-SU-2021:0809-1)
- 174819 SUSE Enterprise Linux Security update for the Linux Kernel (Live Patch 18 for SLE 15) (SUSE-SU-2021:0868-1)
- 239314 Red Hat Update for kernel-rt (RHSA-2021:1739)
- 239339 Red Hat Update for kernel (RHSA-2021:1578)
- 375284 EulerOS Security Update for kernel (EulerOS-SA-2021-1311)
- 390233 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2021-0005)
- 610337 Google Pixel Android May 2021 Security Patch Missing
- 670185 EulerOS Security Update for kernel (EulerOS-SA-2021-1684)
- 671703 EulerOS Security Update for kernel (EulerOS-SA-2022-1735)
- 750376 OpenSUSE Security Update for RT kernel (openSUSE-SU-2021:0242-1)
- 750428 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:0075-1)
- 750434 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:0060-1)
- 940354 AlmaLinux Security Update for kernel (ALSA-2021:1578)