CVE-2020-10690: Canonical Ubuntu Linux
Medium severity, CVSS 6.4. EPSS: 0.4% chance of exploitation in the next 30 days.
There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /dev/ptpX) and voluntarily goes to sleep. During this time if the underlying device is removed, it can cause an exploitable condition as the process wakes up to terminate and clean all attached files. The system crashes due to the cdev structure being invalid (as already freed) which is pointed to by the inode.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
- Debian Debian Linux: version 8.0 only
- Linux Linux Kernel: before 5.5 (fixed in 5.5)
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Element Software: affected versions not specified
- Netapp h300e Firmware: affected versions not specified
- Netapp h300s Firmware: affected versions not specified
- Netapp h410c Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500e Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h610c Firmware: affected versions not specified
- Netapp h610s Firmware: affected versions not specified
- Netapp h615c Firmware: affected versions not specified
- Netapp h700e Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
- Netapp Hci Compute Node: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Opensuse Leap: version 15.1 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
Published 2020-05-08. Last modified 2026-06-17.