CVE-2020-29661 is a high-severity use-after-free vulnerability in the Linux kernel's tty subsystem (drivers/tty/tty_jobctrl.c), affecting versions through 5.9.13, including distributions like Debian, Fedora, and Oracle. This flaw, triggered by a locking issue with TIOCSPGRP, allows a local attacker to achieve high confidentiality, integrity, and availability impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.26, < 4.4.248CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.5, < 4.9.248CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.10, < 4.14.212CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.15, < 4.19.163CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.20, < 5.4.83CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021ctrlX Multiple Vulnerabilities
Apr 23, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021Privilege Escalation via sudo and Linux kernel in Bosch Rexroth Products
Feb 24, 2021A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP aka CID-54ffccbf053b.
Dec 8, 2020kernel: locking issue in drivers/tty/tty_jobctrl.c can lead to an use-after-free
Dec 4, 2020