Rapid7 Vulnerability & Exploit Database

Ubuntu: USN-4419-1 (CVE-2020-10690): Linux kernel vulnerabilities

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Ubuntu: USN-4419-1 (CVE-2020-10690): Linux kernel vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
05/08/2020
Created
08/07/2020
Added
08/05/2020
Modified
03/22/2023

Description

There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition as the process wakes up to terminate and clean all attached files. The system crashes due to the cdev structure being invalid (as already freed) which is pointed to by the inode.

Solution(s)

  • ubuntu-upgrade-linux-image-4-4-0-1074-aws
  • ubuntu-upgrade-linux-image-4-4-0-1076-kvm
  • ubuntu-upgrade-linux-image-4-4-0-1110-aws
  • ubuntu-upgrade-linux-image-4-4-0-1135-raspi2
  • ubuntu-upgrade-linux-image-4-4-0-1139-snapdragon
  • ubuntu-upgrade-linux-image-4-4-0-185-generic
  • ubuntu-upgrade-linux-image-4-4-0-185-generic-lpae
  • ubuntu-upgrade-linux-image-4-4-0-185-lowlatency
  • ubuntu-upgrade-linux-image-4-4-0-185-powerpc-e500mc
  • ubuntu-upgrade-linux-image-4-4-0-185-powerpc-smp
  • ubuntu-upgrade-linux-image-4-4-0-185-powerpc64-emb
  • ubuntu-upgrade-linux-image-4-4-0-185-powerpc64-smp
  • ubuntu-upgrade-linux-image-aws
  • ubuntu-upgrade-linux-image-generic
  • ubuntu-upgrade-linux-image-generic-lpae
  • ubuntu-upgrade-linux-image-generic-lpae-lts-xenial
  • ubuntu-upgrade-linux-image-generic-lts-xenial
  • ubuntu-upgrade-linux-image-kvm
  • ubuntu-upgrade-linux-image-lowlatency
  • ubuntu-upgrade-linux-image-lowlatency-lts-xenial
  • ubuntu-upgrade-linux-image-powerpc-e500mc
  • ubuntu-upgrade-linux-image-powerpc-e500mc-lts-xenial
  • ubuntu-upgrade-linux-image-powerpc-smp
  • ubuntu-upgrade-linux-image-powerpc-smp-lts-xenial
  • ubuntu-upgrade-linux-image-powerpc64-emb
  • ubuntu-upgrade-linux-image-powerpc64-emb-lts-xenial
  • ubuntu-upgrade-linux-image-powerpc64-smp
  • ubuntu-upgrade-linux-image-powerpc64-smp-lts-xenial
  • ubuntu-upgrade-linux-image-raspi2
  • ubuntu-upgrade-linux-image-snapdragon
  • ubuntu-upgrade-linux-image-virtual
  • ubuntu-upgrade-linux-image-virtual-lts-xenial

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;