CVE-2020-29534: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in the Linux kernel before 5.9.3. io_uring takes a non-refcounted reference to the files_struct of the process that submitted a request, causing execve() to incorrectly optimize unshare_fd(), aka CID-0f2122045b94.

Affected products

  • Linux Linux Kernel: from 5.1, before 5.8.18 (fixed in 5.8.18); from 5.9.0, before 5.9.3 (fixed in 5.9.3); version 5.10 only

Published 2020-12-03. Last modified 2026-06-17.