CVE-2020-36385 PUBLISHED

An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.

EPSS 0.05% · 17.1th percentile

Risk Scores

EPSS Score
0.05%
17.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSlinux-ibm0, 5.4.0-1003.4, 5.4.0-1004.5
Ubuntu:20.04:LTSlinux-azure5.4.0-1055.57, 5.4.0-1051.53, 5.4.0-1049.51
Ubuntu:Pro:16.04:LTSlinux-hwe4.15.0-38.41~16.04.1, 4.15.0-39.42~16.04.1, 4.15.0-42.45~16.04.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-gcp-fips4.15.0-2017.19, 4.15.0-2016.18, 0
Ubuntu:18.04:LTSlinux-aws-5.40, 5.4.0-1038.40~18.04.1, 5.4.0-1037.39~18.04.1
Ubuntu:18.04:LTSlinux-gcp-edge4.18.0-1013.14~18.04.1, 4.18.0-1015.16~18.04.1, 5.0.0-1011.11~18.04.1
Ubuntu:18.04:LTSlinux4.15.0-69.78, 4.15.0-161.169, 4.15.0-159.167
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-fips5.4.0-1035.41, 0, 5.4.0-1026.30
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-azure-fips5.4.0-1022.22+fips1, 0
Ubuntu:20.04:LTSlinux-gcp-5.85.8.0-1038.40~20.04.1, 5.8.0-1032.34~20.04.1, 0
Ubuntu:Pro:FIPS:16.04:LTSlinux-fips4.4.0-1067.73, 0, 4.4.0-1003.3
Ubuntu:20.04:LTSlinux-hwe-5.85.8.0-31.33~20.04.1, 5.8.0-33.36~20.04.1, 5.8.0-38.43~20.04.1
Ubuntu:20.04:LTSlinux-gcp5.4.0-1051.55, 5.4.0-1036.39, 5.4.0-1052.56
Ubuntu:18.04:LTSlinux-gcp-5.35.3.0-1032.34~18.04.1, 5.3.0-1030.32~18.04.1, 5.3.0-1029.31~18.04.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-aws-fips4.15.0-2054.56, 4.15.0-2053.55, 4.15.0-2052.54
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1079.86, 4.15.0-1114.123, 4.15.0-1113.122
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1112.124~14.04.1, 4.15.0-1042.46~14.04.1, 4.15.0-1045.49~14.04.1
Ubuntu:20.04:LTSlinux-raspi0, 5.4.0-1007.7, 5.4.0-1008.8
Ubuntu:18.04:LTSlinux-azure4.15.0-1003.3, 4.15.0-1012.12, 4.15.0-1013.13
Ubuntu:18.04:LTSlinux-aws-5.05.0.0-1027.30, 5.0.0-1025.28, 5.0.0-1024.27~18.04.1

…and 64 more

Timeline

References

Open in Interactive Console →