imPC@ndo IT

Tracker / CVE-2020-29660

CVE-2020-29660

Medium 4.4

A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.

Affected products and versions

broadcom fabric_operating_system
debian debian_linux
fedoraproject fedora
linux linux_kernel · … → 5.9.13
netapp 8300_firmware
netapp 8700_firmware
netapp a400_firmware
netapp a700s_firmware
netapp active_iq_unified_manager
netapp h410c_firmware
netapp solidfire_baseboard_management_controller_firmware

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References