Vulnerabilities > CVE-2020-36385 - Use After Free vulnerability in multiple products

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH

Summary

An issue was discovered in the Linux kernel before 5.10. drivers/infiniband/core/ucma.c has a use-after-free because the ctx is reached via the ctx_list in some ucma_migrate_id situations where ucma_close is called, aka CID-f5449e74802c.

Vulnerable Configurations

Part Description Count
OS
Linux
4174
OS
Netapp
8
Hardware
Netapp
8
Application
Starwindsoftware
2

Common Weakness Enumeration (CWE)