CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS
Percentile
5.1%
A flaw possibility of race condition and incorrect initialization of the
process id was found in the Linux kernel child/parent process
identification handling while filtering signal handlers. A local attacker
is able to abuse this flaw to bypass checks to send any signal to a
privileged process.
Author | Note |
---|---|
mdeslaur | possibly Red Hat specific, but bug lists upstream commits, needs investigation |
sbeattie | The upstream commit is with respect to the race condition, not the improper initialization. |
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 20.04 | noarch | linux-riscv-5.8 | < 5.8.0-17.19~20.04.1 | UNKNOWN |
ubuntu | 20.04 | noarch | linux-bluefield | < 5.4.0-1011.14 | UNKNOWN |
ubuntu | 18.04 | noarch | linux | < 4.15.0-129.132 | UNKNOWN |
ubuntu | 20.04 | noarch | linux | < 5.4.0-59.65 | UNKNOWN |
ubuntu | 20.10 | noarch | linux | < 5.8.0-44.50 | UNKNOWN |
ubuntu | 16.04 | noarch | linux | < 4.4.0-198.230 | UNKNOWN |
ubuntu | 14.04 | noarch | linux-aws | < 4.4.0-1083.87 | UNKNOWN |
ubuntu | 18.04 | noarch | linux-aws | < 4.15.0-1091.96 | UNKNOWN |
ubuntu | 20.04 | noarch | linux-aws | < 5.4.0-1034.35 | UNKNOWN |
ubuntu | 20.10 | noarch | linux-aws | < 5.8.0-1024.26 | UNKNOWN |
bugzilla.redhat.com/show_bug.cgi?id=1902724
github.com/torvalds/linux/commit/b4e00444cab4c3f3fec876dc0cccc8cbb0d1a948
launchpad.net/bugs/cve/CVE-2020-35508
lore.kernel.org/kernel-hardening/[email protected]/
mailman-eng.corp.redhat.com/archives/rhkernel-list/2020-December/498644.html
nvd.nist.gov/vuln/detail/CVE-2020-35508
security-tracker.debian.org/tracker/CVE-2020-35508
ubuntu.com/security/notices/USN-4751-1
ubuntu.com/security/notices/USN-4752-1
www.cve.org/CVERecord?id=CVE-2020-35508
CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS
Percentile
5.1%