VYPR
Medium severity5.3NVD Advisory· Published May 12, 2020· Updated Jun 17, 2026

CVE-2020-12826

CVE-2020-12826

Description

A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can send an arbitrary signal to a parent process in a different security domain. Exploitation limitations include the amount of elapsed time before an integer overflow occurs, and the lack of scenarios where signals to a parent process present a substantial operational threat.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • Linux/Linux kerneldescription
  • Linux/Kernelllm-fuzzy2 versions
    <5.6.5+ 1 more
    • (no CPE)range: <5.6.5
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <5.6.5
  • cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:redhat:enterprise_linux:5.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*
  • osv-coords
    Range: < 4.18.0-240.el8

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.