Vulnerabilities > CVE-2020-36557 - Use After Free vulnerability in Linux Kernel

047910
CVSS 5.1 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
high complexity
linux
CWE-416

Summary

A race condition in the Linux kernel before 5.6.2 between the VT_DISALLOCATE ioctl and closing/opening of ttys could lead to a use-after-free.

Vulnerable Configurations

Part Description Count
OS
Linux
4516

Common Weakness Enumeration (CWE)