CVE-2020-27786

NameCVE-2020-27786
DescriptionA flaw was found in the Linux kernels implementation of MIDI, where an attacker with a local account and the permissions to issue an ioctl commands to midi devices, could trigger a use-after-free. A write to this specific memory while freed and before use could cause the flow of execution to change and possibly allow for memory corruption or privilege escalation.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)stretch4.9.228-1fixed
stretch (security)4.9.246-2fixed
buster4.19.160-2fixed
buster (security)4.19.152-1fixed
bullseye5.10.4-1fixed
sid5.10.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcestretch4.9.228-1
linuxsourcebuster4.19.131-1
linuxsource(unstable)5.6.14-1

Notes

https://git.kernel.org/linus/c1f6e3c818dd734c30f6a7eeebf232ba2cf3181d

Search for package or bug name: Reporting problems