CVE-2020-29534: An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct of the process that submitted a request causing execve() to incorrectly optimize unshare_fd() aka CID-0f2122045b94.
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploit Status
- Not Exploited
- Patch Tuesday
- 2020-Dec
- Released
- 2020-12-07
- EPSS Score
- 0.45% (percentile: 37.2%)
Affected Products (1)
Mariner
- cm1 kernel 5.4.91-1 on CBL Mariner 1.0
Revision History
- 2020-12-07: Information published.