[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2LIVEPATCH-2021-031 --- kernel-livepatch-4.14.200-155.322

ID: oval:org.secpod.oval:def:1700588Date: (C)2021-04-12   (M)2024-02-19
Class: PATCHFamily: unix




A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24. A locking vulnerability was found in the tty subsystem of the Linux kernel in drivers/tty/tty_jobctrl.c. This flaw allows a local attacker to possibly corrupt memory or escalate privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability

Platform:
Amazon Linux 2
Product:
kernel-livepatch-4.14.200-155.322
Reference:
ALAS2LIVEPATCH-2021-031
CVE-2020-29660
CVE-2020-29661
CVE    2
CVE-2020-29661
CVE-2020-29660
CPE    1
cpe:/o:amazon:linux:2

© SecPod Technologies