CVE-2020-8428 PUBLISHED

fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an open system call for a UNIX domain socket, if the socket is being moved to a new parent directory and its old parent directory is being removed.

EPSS 0.10% · 27.0th percentile

Risk Scores

EPSS Score
0.10%
27.0th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSlinux-azure4.15.0-1023.24~14.04.1, 4.15.0-1061.66~14.04.1, 4.15.0-1060.65~14.04.1
Ubuntu:18.04:LTSlinux-aws-5.05.0.0-1024.27~18.04.1, 5.0.0-1023.26~18.04.1, 5.0.0-1022.25~18.04.1
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1050.53, 4.15.0-1052.55, 4.15.0-1055.58
Ubuntu:18.04:LTSlinux-azure4.18.0-1019.19~18.04.1, 4.15.0-1035.36, 4.15.0-1032.33
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:16.04:LTSlinux-raspi20, 4.2.0-1013.19, 4.2.0-1014.21
Ubuntu:Pro:14.04:LTSlinux-lts-xenial4.4.0-169.198~14.04.1, 0, 4.4.0-13.29~14.04.1
Ubuntu:22.04:LTSlinux-riscv5.13.0-1007.7+22.04.1, 5.15.0-1027.31, 5.15.0-1026.30
Ubuntu:16.04:LTSlinux-oracle4.15.0-1007.9~16.04.1, 4.15.0-1017.19~16.04.2, 4.15.0-1015.17~16.04.1
Ubuntu:18.04:LTSlinux-gcp-5.35.3.0-1010.11~18.04.1, 5.3.0-1009.10~18.04.1, 5.3.0-1008.9~18.04.1
Ubuntu:18.04:LTSlinux-snapdragon4.15.0-1069.76, 0, 4.4.0-1077.82
Ubuntu:18.04:LTSlinux4.15.0-74.84, 0, 4.15.0-34.37
Ubuntu:18.04:LTSlinux-gke-5.05.0.0-1032.33, 0, 5.0.0-1011.11~18.04.1
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.3.0-1015.17, 5.3.0-1017.19
Ubuntu:18.04:LTSlinux-raspi2-5.30, 5.3.0-1021.23~18.04.1, 5.3.0-1019.21~18.04.1
Ubuntu:16.04:LTSlinux-aws4.4.0-1020.29, 0, 4.4.0-1001.10
Ubuntu:16.04:LTSlinux-snapdragon4.4.0-1102.107, 4.4.0-1100.105, 4.4.0-1099.104
Ubuntu:16.04:LTSlinux-azure4.11.0-1011.11, 4.15.0-1075.80, 4.15.0-1071.76
Ubuntu:18.04:LTSlinux-oracle-5.05.0.0-1009.14~18.04.1, 0, 5.0.0-1010.15~18.04.1
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1068.71+cvm1.1, 5.4.0-1069.72+cvm1.1, 5.4.0-1070.73+cvm1.1

…and 25 more

Timeline

References

Open in Interactive Console →