#VU28160 Race condition in Linux kernel - CVE-2020-12652
Published: May 21, 2020
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition in the "__mptctl_ioctl" function in "drivers/message/fusion/mptctl.c" file. A local administrator can hold an incorrect lock during the ioctl operation, trigger the race and gain unauthorized access to sensitive information and escalate privileges on the system.