ZeroHour

CVE-2020-35508

CVSS 3.1
4.5 medium
EPSS
<1%p13
Published
()
Modified
Description

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

Vendors
linuxredhatnetapp
Products
linux kernel, enterprise linux, a700s firmware, brocade fabric operating system firmware, fas8300 firmware, fas8700 firmware, aff a400 firmware, h300s firmware, h500s firmware, h700s firmware, h300e firmware, h500e firmware
Weakness
CWE-665, CWE-362
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.