CVE-2020-14356
Vulnerability Summary
Timeline
Description
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 1.00%• Percentile: 61%
Techniques & Countermeasures
- CWE-476•NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
Affected Systems
- canonical•ubuntu_linux
14.04 | 16.04 | 18.04 | 20.04
- debian•linux
< 5.7.10-1 | < 5.7.10-1 | < 5.7.10-1 | < 5.7.10-1
- ubuntu•linux
< 4.15.0-118.119 | all | all | all
- ubuntu•linux-aws
< 4.15.0-1083.87 | all | all | all
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.15
all
- ubuntu•linux-aws-5.3
< 5.3.0-1034.36
- ubuntu•linux-aws-5.4
all
- ubuntu•linux-aws-6.8
all
- ubuntu•linux-aws-fips
< 4.15.0-2027.27 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1083.87~16.04.1
- ubuntu•linux-azure
< 4.15.0-1096.106~14.04.1 | < 4.15.0-1096.106~16.04.1 | all | all | all | all
- ubuntu•linux-azure-4.15
< 4.15.0-1096.106
- ubuntu•linux-azure-5.15
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all | all | all
- ubuntu•linux-azure-fde-6.17
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fde-7.0
all
- ubuntu•linux-azure-fips
< 4.15.0-2009.10 | all
- ubuntu•linux-azure-nvidia
all
- ubuntu•linux-bluefield
all | all
- ubuntu•linux-fips
< 4.15.0-1041.46 | all
- ubuntu•linux-gcp
< 4.15.0-1084.95~16.04.1 | all | all | all | all
- ubuntu•linux-gcp-4.15
< 4.15.0-1084.95
- ubuntu•linux-gcp-5.15
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
all
- ubuntu•linux-gcp-6.11
all
- ubuntu•linux-gcp-6.8
all
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-gcp-fips
all
- ubuntu•linux-gke
all | all | all | all
- ubuntu•linux-gke-4.15
< 4.15.0-1070.73
- ubuntu•linux-gke-5.3
< 5.3.0-1034.36
- ubuntu•linux-gkeop
all | all
- ubuntu•linux-hwe
< 4.15.0-118.119~16.04.1 | < 5.3.0-66.60
- ubuntu•linux-hwe-5.15
all
- ubuntu•linux-hwe-5.4
all
- ubuntu•linux-hwe-6.11
all
- ubuntu•linux-hwe-6.8
all
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-ibm
all | all | all | all
- ubuntu•linux-ibm-5.15
all
- ubuntu•linux-ibm-5.4
all
- ubuntu•linux-ibm-6.8
all
Showing first 50 affected entries in server-rendered view.
References (18)
- https://bugzilla.redhat.com/show_bug.cgi?id=1868453
- https://bugzilla.kernel.org/show_bug.cgi?id=208003
- https://lore.kernel.org/netdev/CAM_iQpUKQJrj8wE+Qa8NGR3P0L+5Uz=qo-O5+k_P60HzTde6aw%40mail.gmail.com/t/
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00047.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00007.html
- https://security.netapp.com/advisory/ntap-20200904-0002/
- https://usn.ubuntu.com/4484-1/
- https://usn.ubuntu.com/4483-1/
- https://usn.ubuntu.com/4526-1/
- https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
- https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html
- https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html
- https://ubuntu.com/security/CVE-2020-14356
- https://ubuntu.com/security/notices/USN-4483-1
- https://ubuntu.com/security/notices/USN-4484-1
- https://ubuntu.com/security/notices/USN-4526-1
- https://www.cve.org/CVERecord?id=CVE-2020-14356
- https://security-tracker.debian.org/tracker/CVE-2020-14356