CVE-2020-35508

Updated: 2023-12-06

CWE: Improper Initialization

Description:

A flaw possibility of race condition and incorrect initialization of the process id was found in the Linux kernel child/parent process identification handling while filtering signal handlers. A local attacker is able to abuse this flaw to bypass checks to send any signal to a privileged process.

CVSS3: 4.5


Vendor State

OS Vendor version Errata
Ubuntu 18.04 4.15.0-129.132 USN-4680-1
Ubuntu 16.04 4.4.0-198.230 USN-4681-1
Ubuntu 18.04 AWS 4.15.0-1091.96 USN-4680-1
Ubuntu 16.04 AWS 4.4.0-1119.133 USN-4681-1
Ubuntu 16.04 HWE 4.15.0-129.132~16.04.1 USN-4680-1
Ubuntu 16.04 AWS HWE 4.15.0-1091.96~16.04.1 USN-4680-1
Debian 9 4.9.246-1 DLA-2494-1
Oracle Linux 6 UEK 4 4.1.12-124.50.2.el6uek ELSA-2021-9215
Oracle Linux 7 UEK 4 4.1.12-124.50.2.el7uek ELSA-2021-9215
Ubuntu 18.04 HWE Focal 5.4.0-59.65~18.04.1 USN-4679-1
Ubuntu 16.04 GCP 4.15.0-1091.104~16.04.1 USN-4680-1
RHEL 8 4.18.0-305.el8 RHSA-2021:1578
Ubuntu 16.04 Azure 4.15.0-1103.114~16.04.1 USN-4680-1
CentOS 8 4.18.0-305.el8 CESA-2021:1578
Oracle Linux 8 4.18.0-305.el8 ELSA-2021-1578
Ubuntu 20.04 5.4.0-59.65 USN-4679-1
Ubuntu 18.04 AWS Focal 5.4.0-1034.35~18.04.1 USN-4679-1
Ubuntu 18.04 Azure Focal 5.4.0-1035.36~18.04.1 USN-4679-1
Ubuntu 20.04 AWS 5.4.0-1034.35 USN-4679-1
AlmaLinux 8 4.18.0-305.el8 ALSA-2021:1578
Ubuntu 20.04 HWE 5.8.0-44.50~20.04.1 USN-4751-1
Ubuntu 16.04 HWE ESM 4.15.0-129.132~16.04.1 USN-4680-1
Ubuntu 16.04 AWS ESM 4.4.0-1119.133 USN-4681-1
Ubuntu 16.04 GCP ESM 4.15.0-1091.104~16.04.1 USN-4680-1
Ubuntu 16.04 AWS HWE ESM 4.15.0-1091.96~16.04.1 USN-4680-1
Ubuntu 16.04 Azure ESM 4.15.0-1103.114~16.04.1 USN-4680-1

KernelCare State

OS Original kernel version State
Ubuntu 18.04
Ready For Release
Ubuntu 16.04
Ready For Release
Ubuntu 18.04 AWS
Ready For Release
Ubuntu 16.04 AWS
Ready For Release
Ubuntu 16.04 HWE
Ready For Release
Ubuntu 16.04 AWS HWE
Ready For Release
Debian 9
Will Not Fix
Oracle Linux 6 UEK 4
4.1.12-124.46.4.1.el6uek show all hide all
4.1.12-124.36.4.el6uek 4.1.12-124.23.2.el6uek 4.1.12-124.14.1.el6uek 4.1.12-124.40.6.el6uek 4.1.12-124.21.1.el6uek 4.1.12-124.29.3.el6uek 4.1.12-124.32.3.el6uek 4.1.12-124.36.1.el6uek 4.1.12-124.25.1.el6uek 4.1.12-124.45.2.el6uek 4.1.12-124.48.5.el6uek 4.1.12-124.42.3.el6uek 4.1.12-124.41.4.el6uek 4.1.12-124.33.4.el6uek 4.1.12-124.44.4.el6uek 4.1.12-124.32.1.el6uek 4.1.12-124.39.5.el6uek 4.1.12-124.27.1.el6uek 4.1.12-124.15.2.el6uek 4.1.12-124.18.5.el6uek 4.1.12-124.47.3.el6uek 4.1.12-112.16.7.el6uek 4.1.12-124.14.5.el6uek 4.1.12-124.19.1.el6uek 4.1.12-94.3.5.el6uek 4.1.12-124.29.3.1.el6uek 4.1.12-124.17.1.el6uek 4.1.12-124.34.1.el6uek 4.1.12-124.39.1.el6uek 4.1.12-124.35.1.el6uek 4.1.12-103.9.4.el6uek 4.1.12-124.20.7.el6uek 4.1.12-124.38.1.el6uek 4.1.12-124.16.2.el6uek 4.1.12-112.16.4.el6uek 4.1.12-124.16.1.el6uek 4.1.12-124.16.3.el6uek 4.1.12-124.18.1.el6uek 4.1.12-124.31.1.el6uek 4.1.12-124.32.3.2.el6uek 4.1.12-124.35.2.el6uek 4.1.12-124.35.4.el6uek 4.1.12-124.39.2.el6uek 4.1.12-61.47.1.el6uek 4.1.12-124.27.2.el6uek 4.1.12-124.43.4.el6uek 4.1.12-124.18.9.el6uek 4.1.12-124.15.1.el6uek 4.1.12-124.19.2.el6uek 4.1.12-124.26.10.el6uek 4.1.12-124.28.1.el6uek 4.1.12-124.15.4.el6uek 4.1.12-124.28.6.el6uek 4.1.12-124.45.6.el6uek 4.1.12-124.28.3.el6uek 4.1.12-112.14.13.el6uek 4.1.12-124.14.2.el6uek 4.1.12-124.16.4.el6uek 4.1.12-124.36.3.el6uek 4.1.12-124.30.1.el6uek 4.1.12-124.46.3.el6uek 4.1.12-124.26.12.el6uek 4.1.12-124.20.1.el6uek 4.1.12-112.14.15.el6uek 4.1.12-112.17.3.el6uek 4.1.12-124.14.3.el6uek 4.1.12-124.17.2.el6uek 4.1.12-124.20.3.el6uek 4.1.12-124.22.2.el6uek 4.1.12-124.28.5.el6uek 4.1.12-124.29.4.1.el6uek 4.1.12-124.31.1.1.el6uek 4.1.12-124.36.1.1.el6uek 4.1.12-124.37.1.el6uek 4.1.12-124.39.2.1.el6uek 4.1.12-124.39.5.1.el6uek 4.1.12-124.40.6.2.el6uek 4.1.12-124.40.6.3.el6uek 4.1.12-124.41.5.el6uek 4.1.12-124.42.4.el6uek 4.1.12-124.44.4.1.el6uek 4.1.12-124.48.2.el6uek 4.1.12-124.48.3.1.el6uek 4.1.12-124.48.6.el6uek
Released
Oracle Linux 7 UEK 4
4.1.12-124.20.7.el7uek show all hide all
4.1.12-124.38.1.el7uek 4.1.12-124.27.1.el7uek 4.1.12-124.25.1.el7uek 4.1.12-124.44.4.el7uek 4.1.12-124.41.4.el7uek 4.1.12-124.26.12.el7uek 4.1.12-124.15.2.el7uek 4.1.12-103.9.4.el7uek 4.1.12-124.28.3.el7uek 4.1.12-124.36.3.el7uek 4.1.12-112.14.13.el7uek 4.1.12-124.15.1.el7uek 4.1.12-124.36.4.el7uek 4.1.12-124.17.1.el7uek 4.1.12-112.16.7.el7uek 4.1.12-124.27.2.el7uek 4.1.12-124.45.6.el7uek 4.1.12-124.28.6.el7uek 4.1.12-124.29.3.el7uek 4.1.12-124.48.5.el7uek 4.1.12-124.14.2.el7uek 4.1.12-124.42.3.el7uek 4.1.12-124.35.1.el7uek 4.1.12-124.39.5.el7uek 4.1.12-124.40.6.el7uek 4.1.12-124.43.4.el7uek 4.1.12-124.32.1.el7uek 4.1.12-124.45.2.el7uek 4.1.12-124.28.1.el7uek 4.1.12-124.15.4.el7uek 4.1.12-124.33.4.el7uek 4.1.12-94.3.5.el7uek 4.1.12-124.46.3.el7uek 4.1.12-124.16.2.el7uek 4.1.12-124.34.1.el7uek 4.1.12-124.36.1.el7uek 4.1.12-124.39.1.el7uek 4.1.12-124.30.1.el7uek 4.1.12-124.14.5.el7uek 4.1.12-124.32.3.el7uek 4.1.12-124.29.3.1.el7uek 4.1.12-124.47.3.el7uek 4.1.12-124.14.1.el7uek 4.1.12-124.26.10.el7uek 4.1.12-124.49.3.1.el7uek 4.1.12-124.23.2.el7uek 4.1.12-124.18.9.el7uek 4.1.12-124.16.4.el7uek 4.1.12-112.14.15.el7uek 4.1.12-112.16.4.el7uek 4.1.12-112.17.3.el7uek 4.1.12-124.16.1.el7uek 4.1.12-124.16.3.el7uek 4.1.12-124.18.1.el7uek 4.1.12-124.20.3.el7uek 4.1.12-124.31.1.el7uek 4.1.12-124.32.3.2.el7uek 4.1.12-124.35.2.el7uek 4.1.12-124.35.4.el7uek 4.1.12-124.36.1.1.el7uek 4.1.12-124.39.2.el7uek 4.1.12-124.39.5.1.el7uek 4.1.12-124.14.3.el7uek 4.1.12-124.17.2.el7uek 4.1.12-124.22.2.el7uek 4.1.12-124.28.5.el7uek 4.1.12-124.29.4.1.el7uek 4.1.12-124.31.1.1.el7uek 4.1.12-124.37.1.el7uek 4.1.12-124.39.2.1.el7uek 4.1.12-124.40.6.3.el7uek 4.1.12-124.41.5.el7uek 4.1.12-124.42.4.el7uek 4.1.12-124.44.4.1.el7uek 4.1.12-124.48.2.el7uek 4.1.12-124.48.3.1.el7uek 4.1.12-124.48.6.el7uek 4.1.12-124.46.4.1.el7uek
Released
Ubuntu 18.04 HWE Focal
Ready For Release
Ubuntu 16.04 GCP
Will Not Fix
RHEL 8
4.18.0-240.8.1.el8_3 show all hide all
4.18.0-240.1.1.el8_3 4.18.0-240.15.1.el8_3 4.18.0-240.10.1.el8_3 4.18.0-240.22.1.el8_3 4.18.0-240.el8
Released
Debian 10
Will Not Fix
Proofpoint
Ready For Release
Ubuntu 16.04 Azure
Will Not Fix
CentOS 8
4.18.0-240.22.1.el8_3 show all hide all
4.18.0-240.10.1.el8_3 4.18.0-240.el8 4.18.0-240.15.1.el8_3 4.18.0-240.1.1.el8_3
Released
Oracle Linux 8
4.18.0-240.el8 show all hide all
4.18.0-240.1.1.el8_3 4.18.0-240.10.1.el8_3 4.18.0-240.8.1.el8_3 4.18.0-240.22.1.el8_3 4.18.0-240.15.1.el8_3
Released
CloudLinux OS 8
Will Not Fix
CloudLinux OS 7h
Will Not Fix
Ubuntu 20.04
Ready For Release
Ubuntu 18.04 AWS Focal
Ready For Release
Ubuntu 18.04 Azure Focal
Will Not Fix
Ubuntu 20.04 AWS
Ready For Release
AlmaLinux 8
4.18.0-240.22.1.el8_3 show all hide all
4.18.0-240.15.1.el8_3 4.18.0-240.el8
Released
Ubuntu 20.04 HWE
5.8.0-43.49~20.04.1 show all hide all
5.8.0-38.43~20.04.1 5.8.0-34.37~20.04.2 5.8.0-29.31~20.04.1 5.8.0-33.36~20.04.1 5.8.0-36.40~20.04.1 5.8.0-40.45~20.04.1 5.8.0-41.46~20.04.1
Released
Ubuntu 16.04 HWE ESM
Will Not Fix
Ubuntu 16.04 AWS ESM
Will Not Fix
Ubuntu 16.04 GCP ESM
Will Not Fix
Ubuntu 16.04 AWS HWE ESM
Will Not Fix
Ubuntu 16.04 Azure ESM
Will Not Fix