Description
gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in the Linux kernel through 5.6.10 lacks certain domain_release calls, leading to a memory leak. Note: This was disputed with the assertion that the issue does not grant any access not already available. It is a problem that on unloading a specific kernel module some memory is leaked, but loading kernel modules is a privileged operation. A user could also write a kernel module to consume any amount of memory they like and load that replicating the effect of this bug
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-4483-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-4485-1 | Linux kernel vulnerabilities |
References
History
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:04:22.563Z
Reserved: 2020-05-05T00:00:00.000Z
Link: CVE-2020-12656
Updated: 2024-08-04T12:04:22.563Z
Status : Modified
Published: 2020-05-05T06:15:11.120
Modified: 2024-11-21T05:00:00.270
Link: CVE-2020-12656
OpenCVE Enrichment
No data.
Weaknesses
Ubuntu USN