#VU28416 Use-after-free in Linux kernel


Published: 2020-02-06 | Updated: 2020-06-01

Vulnerability identifier: #VU28416

Vulnerability risk: Low

CVSSv3.1:

CVE-ID: CVE-2020-8648

CWE-ID: CWE-416

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local authenticated user to #BASIC_IMPACT#.

There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.

Mitigation
Install update from vendor's website.

Vulnerable software versions

Linux kernel: 4.4 - 5.5.19


CPE

External links
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.216
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.216
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.109
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.173
http://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.9
http://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.25
http://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability